First 30 to use discount code QP2VOSSH will get 20% off!
Beatrice.py is a tool designed for controlled security research and red/purple team environments. It performs instruction-level patching of x64 executables and binaries while preserving instruction size constraints to maintain binary stability.
The tool is intended to assist security professionals in analyzing how static and dynamic detection systems respond to low-level binary modifications.
Try out the free public version:
https://github.com/raskolnikov90/Beatrice.py
For Red Team, Blue Team, and Purple Team exercises:
- Automates portions of executable modification workflows.
- Assists in evaluating the robustness of detection logic and rule-based systems such as YARA.
- Supports defense validation by creating reproducible binary mutation for testing purposes.
- Beatrice.py can support the making of evasive payloads, specially when combined with other adversary emulation techniques, to evaluate how well endpoint security solutions such as antivirus and EDR systems detect and respond to modified or instrumented binaries. This also helps red and purple team exercises where defensive teams can assess detection coverage, improve alerting logic, and test incident response.
Core features:
- Generate patterns of simple assembly x64 instructions and their alternative instructions, turn them into machine code and patch the machine code if it matches.
- Build different lists of assembly instructions that contain immediate values and other instructions that can’t be easily turned into patterns and apply appropriate changes to them.
- Apply alternative ways to encode instructions whenever possible.
- Create an identical binary functionality wise but with the above patches applied that will help evade YARA rules and some Antivirus solutions.
Pro Edition features:
- More alternative encodings for assembly instructions.
- Parse bytes from YARA rules and DefenderCheck output and use them to generate more patches.
- Parse strings from YARA rules to modify strings on binaries and executable.
- Obfuscate Import Address Table.
- Generate new potential detection bytes that can be used to create YARA rules.
- Includes a PDF showing how the tool can be used for Antivirus and EDR evasion as well as how to use it to test and create detection rules.
- Receive updates for a year as this tool is further improved and refined.
By using this software you agree that:
- You will only use it in fully authorized environments.
- You will not use it for illegal or unauthorized access or modification of systems.
- You assume all responsibility for its use.
- There are no refunds but you can provide feedback and I'll do my best to update the tool and improve on it.