{"adoption": {"forks": 191, "observed_at": "2026-08-28T04:04:06.471286+00:00", "stars": 1242}, "canonical_url": "https://ross.abutalabs.com/products/threadstackspoofer", "card": {"archived": false, "artifact_type": "library", "description": "Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners and analysts.", "domain": ["security", "penetration-testing", "windows"], "enriched": true, "function": ["security", "reverse-engineering"], "health_score": 20, "homepage": null, "language": "C++", "license": "MIT", "license_family": "permissive", "maturity": "maintenance", "member_repos": ["mgeeky/ThreadStackSpoofer"], "name": "mgeeky/ThreadStackSpoofer", "platform": ["windows", "cpp"], "pushed_at": "2022-06-17T18:06:35+00:00", "repo": "mgeeky/ThreadStackSpoofer", "stars": 1242, "tags": ["red-team", "evasion", "shellcode", "call-stack-spoofing", "edr-bypass", "poc", "malware-research"], "topics": [], "urls": [], "use_cases": ["hide shellcode memory allocations from EDR scanners", "spoof thread call stack during red team operations", "bypass thread-based memory examination rules", "study in-memory evasion techniques", "build offensive security tooling with call stack spoofing"], "what_it_is": "A proof-of-concept C++ implementation of thread call stack spoofing, an in-memory evasion technique that hides shellcode references from a thread's call stack. It is aimed at red teamers and security researchers demonstrating how to evade memory scanners, AVs, and EDRs.", "when_to_avoid": ["you need a production-ready, supported security product", "you are looking for defensive detection tooling rather than offensive evasion", "you target non-Windows platforms"], "when_to_choose": ["you need a reference implementation of thread stack spoofing for Windows x64/x86", "you are researching EDR evasion or malware analysis techniques", "you want to improve call stack stealth in red team tooling"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/threadstackspoofer", "repo": "mgeeky/ThreadStackSpoofer", "role": "main", "score": 23}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:06.471286+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T05:08:25.153534+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6f048f9255b61d6de65c36a956a1144cb22ee95df6ec4be23b3ba1fe368b6211", "fetched_at": "2026-08-28T04:04:06.471286+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mgeeky/ThreadStackSpoofer"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:06.471286+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T05:08:25.153534+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6f048f9255b61d6de65c36a956a1144cb22ee95df6ec4be23b3ba1fe368b6211", "fetched_at": "2026-08-28T04:04:06.471286+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mgeeky/ThreadStackSpoofer"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T05:08:25.153534+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6f048f9255b61d6de65c36a956a1144cb22ee95df6ec4be23b3ba1fe368b6211", "fetched_at": "2026-08-28T04:04:06.471286+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mgeeky/ThreadStackSpoofer"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:06.471286+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:06.471286+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:06.471286+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T05:08:25.153534+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6f048f9255b61d6de65c36a956a1144cb22ee95df6ec4be23b3ba1fe368b6211", "fetched_at": "2026-08-28T04:04:06.471286+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mgeeky/ThreadStackSpoofer"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:06.471286+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:06.471286+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T05:08:25.153534+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6f048f9255b61d6de65c36a956a1144cb22ee95df6ec4be23b3ba1fe368b6211", "fetched_at": "2026-08-28T04:04:06.471286+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mgeeky/ThreadStackSpoofer"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:06.471286+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:06.471286+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:06.471286+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T05:08:25.153534+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6f048f9255b61d6de65c36a956a1144cb22ee95df6ec4be23b3ba1fe368b6211", "fetched_at": "2026-08-28T04:04:06.471286+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mgeeky/ThreadStackSpoofer"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:06.471286+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:06.471286+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T05:08:25.153534+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6f048f9255b61d6de65c36a956a1144cb22ee95df6ec4be23b3ba1fe368b6211", "fetched_at": "2026-08-28T04:04:06.471286+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mgeeky/ThreadStackSpoofer"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T05:08:25.153534+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6f048f9255b61d6de65c36a956a1144cb22ee95df6ec4be23b3ba1fe368b6211", "fetched_at": "2026-08-28T04:04:06.471286+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mgeeky/ThreadStackSpoofer"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T05:08:25.153534+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6f048f9255b61d6de65c36a956a1144cb22ee95df6ec4be23b3ba1fe368b6211", "fetched_at": "2026-08-28T04:04:06.471286+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mgeeky/ThreadStackSpoofer"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T05:08:25.153534+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6f048f9255b61d6de65c36a956a1144cb22ee95df6ec4be23b3ba1fe368b6211", "fetched_at": "2026-08-28T04:04:06.471286+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mgeeky/ThreadStackSpoofer"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 8}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 1802, "days_push": 1538, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 23, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}