Ross ROSS = Recommend OSS · open-source software intelligence for agents

T4y1oR/RingQ

一款后渗透免杀工具,助力每一位像我这样的脚本小子快速实现免杀,支持bypass AV/EDR 360 火绒 Windows Defender Shellcode Loader observed · 2026-08-28

github.com/T4y1oR/RingQ · C++ observed · 2026-08-28

Health v2 · maintenance only

27/100

  • Activity 7
  • Release rhythm 35
  • Longevity 60

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 844
  • days_rel: n/a
  • days_push: 560
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1497 stars · 149 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

RingQ is a post-exploitation antivirus evasion tool that obfuscates and loads arbitrary Windows executables or shellcode (e.g., Cobalt Strike, fscan, mimikatz) to bypass AV/EDR products like 360, Huorong, and Windows Defender. It generates an obfuscated payload file with Create.exe and loads it on the target machine with anti-sandbox techniques built in.

Use cases

  • bypass windows defender to run mimikatz
  • evade 360 and huorong antivirus detection
  • load cobalt strike shellcode without getting flagged
  • convert exe tools to obfuscated shellcode loaders
  • run pentest tools on av-protected windows machines
  • anti-sandbox shellcode execution

When to choose

  • you need quick AV/EDR evasion for post-exploitation tooling on Windows
  • you want a simple obfuscate-and-load workflow without writing your own loader
  • you need to bypass 360 QVM, Huorong, or Defender heuristics

When to avoid

  • you need a maintained, licensed security product for production use
  • your use case is defensive security or malware analysis rather than offensive testing
  • you require cross-platform support beyond Windows

Facets

cli-tool · maturity active

security cryptography reverse-engineering security penetration-testing windows windows cpp antivirus-evasion shellcode-loader post-exploitation red-team malware-obfuscation bypass-av-edr

1 source

Member repositories

RepositoryRoleHealth v2
T4y1oR/RingQmain27

For agents

markdown · JSON · MCP: product_card(name="T4y1oR/RingQ")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem