# T4y1oR/RingQ

一款后渗透免杀工具，助力每一位像我这样的脚本小子快速实现免杀，支持bypass AV/EDR 360 火绒 Windows Defender Shellcode Loader

Repository: https://github.com/T4y1oR/RingQ
Canonical: https://ross.abutalabs.com/products/ringq
Language: C++
License Family: other
Last push: 2025-02-19T05:25:52+00:00

## Health v2 (maintenance only)
Score: 27/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 7, release rhythm 35, longevity 60
- inputs: {"age_days": 844, "days_push": 560, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1497, forks 149 (observed 2026-08-28T04:04:53.824874+00:00)

## What it is
RingQ is a post-exploitation antivirus evasion tool that obfuscates and loads arbitrary Windows executables or shellcode (e.g., Cobalt Strike, fscan, mimikatz) to bypass AV/EDR products like 360, Huorong, and Windows Defender. It generates an obfuscated payload file with Create.exe and loads it on the target machine with anti-sandbox techniques built in.

## Use cases
- bypass windows defender to run mimikatz
- evade 360 and huorong antivirus detection
- load cobalt strike shellcode without getting flagged
- convert exe tools to obfuscated shellcode loaders
- run pentest tools on av-protected windows machines
- anti-sandbox shellcode execution

## When to choose
- you need quick AV/EDR evasion for post-exploitation tooling on Windows
- you want a simple obfuscate-and-load workflow without writing your own loader
- you need to bypass 360 QVM, Huorong, or Defender heuristics

## When to avoid
- you need a maintained, licensed security product for production use
- your use case is defensive security or malware analysis rather than offensive testing
- you require cross-platform support beyond Windows

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, cryptography, reverse-engineering
- domain: security, penetration-testing, windows
- platform: windows, cpp
- tags: antivirus-evasion, shellcode-loader, post-exploitation, red-team, malware-obfuscation, bypass-av-edr

## Member repositories
- T4y1oR/RingQ (main) score 27

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:53.824874+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:33:08.095896+00:00, confidence not recorded.
  - readme: https://github.com/T4y1oR/RingQ (fetched 2026-08-28T04:04:53.824874+00:00, sha d8e7b22a8832)
- Data as of 2026-08-30T08:39:29.467469+00:00.
