Ross ROSS = Recommend OSS · open-source software intelligence for agents

hlldz/Phant0m

Windows Event Log Killer observed · 2026-08-28

github.com/hlldz/Phant0m · C · archived observed · 2026-08-28

Health v2 · maintenance only

10/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases archived no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3410
  • days_rel: n/a
  • days_push: 1077
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1812 stars · 305 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Phant0m is a Windows Event Log Killer that identifies the process hosting the Windows Event Log service and terminates only its threads, so logging stops while the service appears to be running. It is written in C, supports multiple PID detection (SCM/WMI) and thread-killing techniques, and can be used standalone or via reflective DLL loading in tools like Cobalt Strike.

Use cases

  • stop windows event logging during a red team engagement
  • kill event log service threads without stopping the process
  • evade detection by disabling windows event logs
  • integrate log-killing capability into cobalt strike via reflective dll
  • test blue team detection of event log tampering

When to choose

  • you are a red teamer needing to halt Windows event log collection while keeping the service process alive
  • you want a configurable tool with multiple PID detection and thread-kill techniques
  • you need in-memory execution via reflective DLL injection from a C2 framework

When to avoid

  • you need to legitimately manage or configure Windows Event Logs
  • you require a licensed or supported tool for production environments
  • you are on a non-Windows platform

Facets

cli-tool · maturity maintenance

security penetration-testing security penetration-testing windows windows cli offensive-security red-team event-log defense-evasion cobalt-strike reflective-dll powershell c2 command-line

1 source

Member repositories

RepositoryRoleHealth v2
hlldz/Phant0mmain10

For agents

markdown · JSON · MCP: product_card(name="hlldz/Phant0m")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem