picaro
A declarative PE packer for authorized red team research — a PE, a DLL or raw shellcode plus a YAML plan becomes a packed binary with the evasion techniques you select.
The docs in one screen
Section titled “The docs in one screen”- Getting started — requirements, a first plan, and the build → run → measure loop.
- Plan — every block of a schema-6 document, plus the interactive wizard that writes one.
- Examples — the runnable plans and recipes.
- Techniques — the Preparation / Execution / Control model and one page per runtime technique.
- Loader features — the cross-cutting stub configuration: syscall layer, API resolution, string obfuscation and payload arguments.
- Architecture — how the packer and the generated stub fit together, and custom stubs.
The Markdown under docs/ is the single source of truth. The per-technique and
per-feature pages, the plan reference and the examples page are pulled from
src/techniques/<name>/README.md, src/features/<name>/README.md, README.md
and examples/README.md at build time, so they never drift.