Veil Framework – Antivirus Evasion Framework


The Veil-Framework is a collection of red team security tools that implement various attack methods focused on antivirus evasion and evading detection.

Antivirus ‘solutions’ don’t often catch the bad guys, but they do often catch pen-testing during assignment. This tool came about as a way to execute existing shellcode in a way that could evade AV engines without rolling a new backdoor each time.

Veil Antivirus Evasion Framework

It currently consists of:

  • Veil-Evasion: a tool to generate antivirus-evading payloads using a variety of techniques and languages
  • Veil-Ordnance: a tool that can be used to quickly generate valid stager shellcode
  • Veil-Catapult: a psexec-style payload delivery system that integrates Veil-Evasion
  • Veil-Pillage: a modular post-exploitation framework that integrates Veil-Evasion
  • Veil-PowerView: a powershell tool to gain network situational awareness on Windows domains

The Approach

Veil Evasion does its’ work by:

  • Using an aggregation of various shellcode injection techniques across multiple languages
  • Having a focus on automation, usability, and developing a true framework
  • Using some shellcodeless Meterpreter stagers and “auxiliary” modules as well

One new payload is released each month with 30+ published payload modules.

You can download Veil Framework here (this is the ‘super’ project that will pull down the latest version of each tool):

Veil-Framework-Install.sh

Or read more here.

Posted in: Hacking Tools, Malware


Latest Posts:


ZigDiggity - ZigBee Hacking Toolkit ZigDiggity – ZigBee Hacking Toolkit
ZigDiggity a ZigBee Hacking Toolkit is a Python-based IoT (Internet of Things) penetration testing framework targeting the ZigBee smart home protocol.
RandIP - Network Mapper To Find Servers RandIP – Network Mapper To Find Servers
RandIP is a nim-based network mapper application that generates random IP addresses and uses sockets to test whether the connection is valid or not with additional tests for Telnet and SSH.
Nipe - Make Tor Default Gateway For Network Nipe – Make Tor Default Gateway For Network
Nipe is a Perl script to make Tor default gateway for network, this script enables you to directly route all your traffic from your computer to the Tor network.
Mosca - Manual Static Analysis Tool To Find Bugs Mosca – Manual Static Analysis Tool To Find Bugs
Mosca is a manual static analysis tool written in C designed to find bugs in the code before it is compiled, much like a grep unix command.
Slurp - Amazon AWS S3 Bucket Enumerator Slurp – Amazon AWS S3 Bucket Enumerator
Slurp is a blackbox/whitebox S3 bucket enumerator written in Go that can use a permutations list to scan externally or an AWS API to scan internally.
US Government Cyber Security Still Inadequate US Government Cyber Security Still Inadequate
Surprise, surprise, surprise - an internal audit of the US Government cyber security situation has uncovered widespread weaknesses, legacy systems and poor adoption of cyber controls and tooling.


Comments are closed.