3-day longest streak
Hi there!👋 🌱 Windows Reversing, Exploit, x86, Malware 📫 Contact: [email protected]…
-
RunPE-In-Memory
Run a Exe File (PE Module) in memory (like an Application Loader)
C++ ★ 944 5y agoExplain → -
PR0CESS
some gadgets about windows process and ready to use :)
C ★ 615 2y agoExplain → -
Skrull
Skrull is a malware DRM, that prevents Automatic Sample Submission by AV/EDR and Signature Scanning from Kernel. It generates launchers that can run malware on the victim using the Process Ghosting technique. Also, launchers are totally anti-copy and naturally broken when got submitted.
C ★ 461 4y agoExplain → -
Windows-APT-Warfare
著作《Windows APT Warfare:惡意程式前線戰術指南》各章節技術實作之原始碼內容
C++ ★ 423 2y agoExplain → -
wowInjector
PoC: Exploit 32-bit Thread Snapshot of WOW64 to Take Over $RIP & Inject & Bypass Antivirus HIPS (HITB 2021)
C ★ 164 5y agoExplain → -
my-Little-Ransomware
easy ransomware module base on csharp.
C# ★ 129 10y agoExplain → -
sakeInject
Windows PE - TLS (Thread Local Storage) Injector in C/C++
C ★ 109 5y agoExplain → -
wowGrail
PoC: Rebuild A New Path Back to the Heaven's Gate (HITB 2021)
C++ ★ 108 5y agoExplain → -
buyHouseAnalyzer
開源台灣房市在線實價登錄分析工具
HTML ★ 72 2y agoExplain → -
puzzCode
simple compiler based on mingw to build uncrackable windows application against analysis tools
C# ★ 63 8y agoExplain → -
wow64Jit
Call 32bit NtDLL API directly from WoW64 Layer
C++ ★ 61 5y agoExplain → -
shellDev.py
tool for building windows shellcode in C by MinGW
Python ★ 55 4y agoExplain → -
theArk
Windows x86 PE Packer In C++
C++ ★ 52 6y agoExplain → -
SignThief
Windows PE Signature Thief in C++
C++ ★ 51 5y agoExplain → -
vibe-reading
氛圍閱讀 Vibe Reading — 離線 PDF 逐段翻譯 Chrome 擴充,基於 Chrome 內建 Gemini Nano / Translator API
JavaScript ★ 47 5d agoExplain → -
xlsKami
Out-of-the-Box Tool to Obfuscate Excel XLS. Include Obfuscation & Hide for Cell Labels & BoundSheets
C# ★ 47 4y agoExplain → -
vtMal
Malware Sandbox Emulation in Python @ HITCON 2018
Python ★ 46 7y agoExplain → -
The-Purified-Elements
The Purified Windows 11: without Defender, Updater, Patches, System Health, etc.
★ 45 2y agoExplain → -
ntkrnlProtectScan
One Click Tool to Scan All the Enabled Protection of current Windows NT Kernel
PowerShell ★ 45 2y agoExplain → -
xlsGen
(PoC) Tiny Excel BIFF8 Generator, to Embedded 4.0 Macros in xls files without Excel.
C# ★ 44 4y agoExplain → -
HellKitty-In-VC
Ring3 Rootkit Backdoor.
C++ ★ 42 11y agoExplain → -
masqueradeCmdline
A PoC to demo modifying cmdline of the child process dynamically. It might be useful against process log tracing, AV or EDR.
C++ ★ 40 5y agoExplain → -
madPocket ⑂
Play PokémonGo From Home, No Jailbreak!
Objective-C++ ★ 38 10y agoExplain → -
dnLauncher
No description.
C ★ 37 4y agoExplain → -
winInject101
Windows Injection 101: from Zero to ROP (HITCON 2017)
C++ ★ 28 8y agoExplain → -
knownDlls_Poison
No description.
C ★ 27 4y agoExplain → -
funcTracker
Useful Plugin for IDA to Trace Function Call Tree
Python ★ 26 8y agoExplain → -
CrackShield-MapleStory-Hack
MapleStory Hack Plugin
Pascal ★ 25 11y agoExplain → -
Win-Exploit-Inject
PoC for DEF CON 26: Playing Malware Injection with Exploit thoughts
C++ ★ 25 7y agoExplain → -
Lexa
Windows Application Loader Running *.Exe files in Memory against Scrylla
C ★ 21 6y agoExplain → -
APCInjector-BYPASS-AV
No description.
C++ ★ 19 11y agoExplain → -
isuMaster-NodeJS
義守管家線上雲端服務
JavaScript ★ 18 9y agoExplain → -
Whisper.py
白癡喔還要下 pip install 誰會用啦—隨開即用 Windows 版 OpenAI Whisper 逐字稿產生器
Python ★ 17 2y agoExplain → -
OpenClam
Windows 桌面 AI 搜尋列、翻譯面板、本地 AI 助手。OpenClam 提供類似 PowerToys Run / Fluent Search 的懸浮搜尋體驗,並整合本地 AI 問答與即時翻譯。
Python ★ 16 2mo agoExplain → -
PykemonGo
Play PokémonGo without hands, Based on Python, and Easy to fix.
Python ★ 15 10y agoExplain → -
moska
Tiny Windows x86 Assembly Compiler in C++ and Keystone Engine
C ★ 14 5y agoExplain → -
goodGarena
Garena 競時通順暢開遊戲小補丁
C++ ★ 13 3y agoExplain → -
WebBrowser-Control-GET-POST-Request-Hook-In-CSharp
Catch All HTTP Request In IE WebBrowser Control In C#
C# ★ 11 11y agoExplain → -
PowerCursor
Auto Move Your Cursor to the Focused Window while You Alt-Tab or Touchboard for Windows
C# ★ 10 1y agoExplain → -
OSX-Dyanmic-Hook
inline hook functions in memory on OSX
C ★ 10 10y agoExplain → -
PkZIP-Unarchiver-in-C
Make stored PkZIP file unarchive in C
C ★ 8 10y agoExplain → -
Chakra
Instagram 限時動態自動閱讀器
Python ★ 8 6y agoExplain → -
NTUSTxTDOH-Reversing-Game
NTUSTxTDOH 2015/11/15~29 Easy Crack Me
C++ ★ 8 10y agoExplain → -
Algorithm
一些演算法學習筆記
C++ ★ 7 9y agoExplain → -
Win32-Debugger
用CBuilder自幹Win32的除錯器.(搭配WinAPI)
Pascal ★ 7 11y agoExplain → -
vodka
.NET PE file parser in C/C++
C++ ★ 6 5y agoExplain → -
engExamSystem-NodeJS
基於 NodeJS 開發的英文克漏字線上測驗系統
JavaScript ★ 6 9y agoExplain → -
Word2Vec.py
Word2Vec written in pure Numpy
Python ★ 6 3y agoExplain → -
disCIL
CIL (MSIL) Disassembler Written In Pure C/C++. Rewrite from Mono Project
C++ ★ 5 5y agoExplain → -
BiuBiu
Control-Flow-Graph Analysis based on Radare2 In Python3
Python ★ 5 6y agoExplain → -
Dad-sRoot
Easy Process Spy For Windows7 x32bit
Pascal ★ 5 10y agoExplain → -
Obfuscate ⑂
Guaranteed compile-time string literal obfuscation header-only library for C++14
★ 4 5y agoExplain → -
Defeat-Defender ⑂
Powerful batch script to dismantle complete windows defender protection and even bypass tamper protection
★ 4 5y agoExplain → -
IconJector ⑂
Unorthodox and stealthy way to inject a DLL into the explorer using icons
★ 4 2y agoExplain → -
PoE-Mutli-Game-And-Auto-UpDate
以C++Builder開發的會自我更新的POE流亡闇道多開.
C++ ★ 4 11y agoExplain → -
cpuZero
a simple CPU0 simulator in C++
C++ ★ 4 9y agoExplain → -
nt5src ⑂
Source code of Windows XP (NT5). Leaks are not from me. I just extracted the archive and cabinet files.
★ 3 4y agoExplain → -
PromptCopy
No description.
C# ★ 3 1y agoExplain → -
easyPunk
白癡喔,打個 CyberPunk 一直卡中文輸入法怎玩啦?
C# ★ 3 3y agoExplain → -
PE_Toy
No description.
C++ ★ 3 5y agoExplain → -
CSharp-Hosts-HTTP-Hook
酷狗音樂破解
C# ★ 3 11y agoExplain → -
24h2-nt-exploit ⑂
Exploit targeting NT kernel in 24H2 Windows Insider Preview
★ 3 2y agoExplain → -
googMeow
Google Search Ninja based on Python
Python ★ 3 9y agoExplain → -
oracle-machine
No description.
Python ★ 2 23d agoExplain → -
capa ⑂
The FLARE team's open-source tool to identify capabilities in executable files.
★ 2 4y agoExplain → -
KernelFuzzer ⑂
Cross Platform Kernel Fuzzer Framework
C ★ 2 9y agoExplain → -
defendnot ⑂
An even funnier way to disable windows defender. (through WSC api)
★ 2 1y agoExplain → -
Ahri
Control Graph based JIT Engine as PE Packer (Python3 + Radare2 + Keystone)
Python ★ 2 6y agoExplain → -
process_doppelganging ⑂
My implementation of enSilo's Process Doppelganging (PE injection technique)
C ★ 2 5y agoExplain → -
process_ghosting ⑂
No description.
★ 2 5y agoExplain → -
PrivFu ⑂
Kernel mode WinDbg extension and PoCs for token privilege investigation.
★ 2 1y agoExplain → -
QACInjector-In-CBuilder
QAC Thread DLL Inector
C++ ★ 2 11y agoExplain → -
HTTPs-WebClient-In-CBuilder
封裝的CBuilder HTTPs封包處理類別,支持本地儲存Cookie,UA設定
C++ ★ 2 11y agoExplain → -
pytorch-lesson-zh ⑂
pytorch 包教不包会
★ 2 7y agoExplain → -
ReflectiveDLLInjection ⑂
Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a library from memory into a host process.
C ★ 2 12y agoExplain → -
Zhuyin-Typo ⑂
Converting wrongly typed English strings back to Zhuyin.
★ 2 11y agoExplain → -
Windows-Digital-Signature-Verify-Tool
a tool with GUI is used to check all digital signature of modules in the process.
C# ★ 2 10y agoExplain → -
iced ⑂
High performance and correct x86/x64 disassembler, assembler, decoder, encoder for .NET, Rust, JavaScript
★ 2 5y agoExplain → -
NautilusProject ⑂
A collection of weird ways to execute unmanaged code in .NET
★ 2 5y agoExplain → -
picoGPT ⑂
No description.
★ 2 3y agoExplain → -
dc30-space-jam ⑂
Resources and demos from the DEFCON 30 Brief "Space Jam: Exploring Radio Frequency Attacks in Outer Space" by James Pavur
★ 2 3y agoExplain → -
EDRSilencer ⑂
A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.
★ 2 2y agoExplain → -
injdrv ⑂
proof-of-concept Windows Driver for injecting DLL into user-mode processes using APC
★ 2 5y agoExplain → -
Virus-Patten-API-Call
No description.
C++ ★ 2 10y agoExplain → -
RedTeamTools ⑂
记录自己编写、修改的部分工具
★ 2 5y agoExplain → -
VMProtect-Source ⑂
Source of VMProtect (NOT OFFICIALLY)
★ 1 3y agoExplain → -
DriverJack ⑂
Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths
★ 1 1y agoExplain → -
Being-A-Good-CLR-Host ⑂
No description.
★ 1 1y agoExplain → -
OffensiveVBA ⑂
This repo covers some code execution and AV Evasion methods for Macros in Office documents
★ 1 4y agoExplain → -
twitter-sentiment-cnn ⑂
An implementation in TensorFlow of a convolutional neural network (CNN) to perform sentiment classification on tweets.
★ 1 8y agoExplain → -
CVE-2024-30090 ⑂
CVE-2024-30090 - LPE PoC
★ 1 1y agoExplain → -
pytorch-seq2seq ⑂
Tutorials on implementing a few sequence-to-sequence (seq2seq) models with PyTorch and TorchText.
★ 1 2y agoExplain → -
BlueTeam-Tools ⑂
Tools and Techniques for Blue Team / Incident Response
★ 1 2y agoExplain → -
Malware-Detection-Using-Machine-Learning ⑂
Multi-class malware classification using Deep Learning
★ 1 5y agoExplain → -
packerPE32 ⑂
Simple PE packer with RtlCompressBuffer
★ 1 10y agoExplain → -
UacBypass ⑂
A demo to bypass windows 10 default UAC configuration using IFileOperation and dll hijacking
C++ ★ 1 10y agoExplain → -
ConfuserEx ⑂
An open-source, free protector for .NET applications
C# ★ 1 10y agoExplain → -
code ⑂
Code for the book "Mastering OpenCV with Practical Computer Vision Projects" by Packt Publishing 2012.
C++ ★ 1 9y agoExplain → -
MD5 ⑂
C implementation of the MD5 algorithm
C ★ 1 9y agoExplain → -
Execute-CSharp-From-XSLT-TEST ⑂
No description.
XSLT ★ 1 9y agoExplain → -
rewolf-wow64ext ⑂
Helper library for x86 programs that runs under WOW64 layer on x64 versions of Microsoft Windows operating systems.
★ 1 8y agoExplain → -
bypassuac ⑂
bypass uac
★ 1 8y agoExplain → -
A-Protect ⑂
fork from A-Protect
★ 1 7y agoExplain → -
SafetyKatz ⑂
SafetyKatz is a combination of slightly modified version of @gentilkiwi's Mimikatz project and @subtee's .NET PE Loader
★ 1 6y agoExplain → -
line-py ⑂
LINE Messaging's private API
★ 1 6y agoExplain → -
CLRExplorer ⑂
Explore .NET Processes and Dump files
★ 1 6y agoExplain → -
windows-priv ⑂
Windows Privilege Escalation
★ 1 5y agoExplain → -
base64 ⑂
base64 c implementation
★ 1 5y agoExplain → -
PolyHook_2_0 ⑂
C++17, x86/x64 Hooking Libary v2.0
★ 1 5y agoExplain → -
REDasm ⑂
The OpenSource Disassembler
★ 1 5y agoExplain → -
v8-internals ⑂
面向编译器开发人员的V8内部实现文档
★ 1 5y agoExplain → -
YOS ⑂
YourtionOS 基于 30dayMakeOS (OSASK) 构建你自己的操作系统
★ 1 5y agoExplain → -
CLRHost ⑂
Demonstrates hosting CLR objects from x86_64 assembly
★ 1 5y agoExplain → -
CertStealer ⑂
A .NET tool for exporting and importing certificates without touching disk.
★ 1 5y agoExplain → -
xorstr ⑂
heavily vectorized c++17 compile time string encryption.
★ 1 5y agoExplain → -
RemotePotato0 ⑂
Just another "Won't Fix" Windows Privilege Escalation from User to Domain Admin.
★ 1 5y agoExplain → -
NoVmp ⑂
A static devirtualizer for VMProtect x64 3.x. powered by VTIL.
★ 1 5y agoExplain → -
LazySign ⑂
Create fake certs for binaries using windows binaries and the power of bat files
★ 1 4y agoExplain → -
HDE64 ⑂
Hacker Disassembler Engine 64 Copyright (c) 2008-2009, Vyacheslav Patkov. * All rights reserved.
★ 1 4y agoExplain → -
pylnk ⑂
Python library for reading and writing Windows shortcut files (.lnk). Python 3 only.
★ 1 3y agoExplain → -
FileSquattingExample ⑂
FileSquatting Exploitation by Example
★ 1 6y agoExplain → -
I-S00N ⑂
No description.
★ 1 2y agoExplain → -
EDR-Preloader ⑂
An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer
★ 1 2y agoExplain → -
aaaddress1
No description.
★ 1 4y agoExplain → -
VMPilot ⑂
VMPilot: A Modern C++ Virtual Machine SDK
★ 1 2y agoExplain → -
CreateProcess ⑂
A small PoC that creates processes in Windows
★ 1 3y agoExplain → -
NerfDefender ⑂
BOF and C++ implementation of the Windows Defender sandboxing technique described by Elastic Security Labs/Gabriel Landau.
★ 1 3y agoExplain → -
avred ⑂
Analyse your malware to surgically obfuscate it
★ 1 2y agoExplain → -
angryorchard ⑂
A kernel vulnerability used to achieve arbitrary read-write on Windows prior to July 2022
★ 1 3y agoExplain → -
ExtremeDumper ⑂
.NET Assembly Dumper
★ 1 5y agoExplain → -
vivisect ⑂
No description.
★ 1 4y agoExplain → -
Mediatek-Fuzzing-Workshop ⑂
Mediatek Fuzzing Workshop in HITCON 2021
C++ ★ 1 4y agoExplain → -
winapi-deobfuscation ⑂
Towards Generic Deobfuscation of Windows API Calls
★ 1 7y agoExplain → -
flare-floss ⑂
FireEye Labs Obfuscated String Solver - Automatically extract obfuscated strings from malware.
Python ★ 1 8y agoExplain → -
winchecksec ⑂
Checksec, but for Windows: static detection of security mitigations in executables
★ 1 5y agoExplain → -
uthenticode ⑂
A cross-platform library for verifying Authenticode signatures
★ 1 5y agoExplain → -
SIPIT ⑂
Official Implementation of SIPIT from "Language Models are Injective and Hence Invertible" (ICLR 2026) :trophy:
★ 0 4mo agoExplain → -
nucleus ⑂
Clone of "Compiler-Agnostic Function Detection in Binaries" source code
★ 0 4y agoExplain → -
Invincea ⑂
This is the implementation of "Deep Neural Network Based Malware Detection Using Two Dimensional Binary Program Features"
★ 0 6y agoExplain → -
CVE-2025-48799 ⑂
No description.
★ 0 11mo agoExplain → -
ComDotNetExploit ⑂
A C++ proof of concept demonstrating the exploitation of Windows Protected Process Light (PPL) by leveraging COM-to-.NET redirection and reflection techniques for code injection. This PoC showcases bypassing code integrity checks and loading malicious payloads in highly protected processes such as LSASS. Based on research from James Forshaw.
★ 0 1y agoExplain → -
LLM4Decompile ⑂
Reverse Engineering: Decompiling Binary Code with Large Language Models
★ 0 1y agoExplain → -
transformers-tutorials ⑂
Github repo with tutorials to fine tune transformers for diff NLP tasks
★ 0 2y agoExplain → -
aaaddress1.github.io
No description.
HTML ★ 0 1y agoExplain → -
Priv2Admin ⑂
Exploitation paths allowing you to (mis)use the Windows Privileges to elevate your rights within the OS.
★ 0 3y agoExplain → -
MTBook ⑂
《机器翻译:基础与模型》肖桐 朱靖波 著 - Machine Translation: Foundations and Models
★ 0 1y agoExplain → -
CVE-2024-7479_CVE-2024-7481 ⑂
TeamViewer User to Kernel Elevation of Privilege PoC. CVE-2024-7479 and CVE-2024-7481. ZDI-24-1289 and ZDI-24-1290. TV-2024-1006.
★ 0 1y agoExplain → -
DotNetHooking ⑂
Sample use cases of the .NET native code hooking technique
★ 0 8y agoExplain → -
Malware-Detection-API-Sequence-Intrinsic-Features ⑂
No description.
★ 0 3y agoExplain → -
phnt ⑂
Native API header files for the System Informer project.
★ 0 1y agoExplain → -
cs230-code-examples ⑂
Code examples in pyTorch and Tensorflow for CS230
★ 0 3y agoExplain → -
Attention-PyTorch ⑂
注意力机制实践
★ 0 3y agoExplain → -
AsmDepictor ⑂
Official implementation of AsmDepictor, "A Transformer-based Function Symbol Name Inference Model from an Assembly Language for Binary Reversing", In the 18th ACM Asia Conference on Computer and Communications Security AsiaCCS '2023
★ 0 2y agoExplain → -
process-cloning ⑂
The Definitive Guide To Process Cloning on Windows
★ 0 2y agoExplain → -
KExecDD ⑂
Admin to Kernel code execution using the KSecDD driver
★ 0 2y agoExplain → -
nanoRWKV ⑂
The nanoGPT-style implementation of RWKV Language Model - an RNN with GPT-level LLM performance.
Python ★ 0 2y agoExplain → -
SharpLink ⑂
Create file system symbolic links from low privileged user accounts within PowerShell
★ 0 4y agoExplain → -
CVE-2023-36884-MS-Office-HTML-RCE ⑂
MS Office and Windows HTML RCE (CVE-2023-36884) - PoC and exploit
★ 0 2y agoExplain → -
file-archiver-in-the-browser ⑂
No description.
★ 0 3y agoExplain → -
StopDefender ⑂
Stop Windows Defender programmatically
★ 0 3y agoExplain → -
manual-syscall-detect ⑂
A tool for detecting manual/direct syscalls in x86 and x64 processes using Nirvana Hooks.
★ 0 4y agoExplain → -
Terminator ⑂
Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes
★ 0 3y agoExplain → -
akamai-security-research ⑂
This repository includes code and IoCs that are the product of research done in Akamai's various security research teams.
★ 0 2y agoExplain → -
rp ⑂
rp++ is a fast C++ ROP gadget finder for PE/ELF/Mach-O x86/x64/ARM/ARM64 binaries.
★ 0 3y agoExplain → -
KernelForge ⑂
A library to develop kernel level Windows payloads for post HVCI era
★ 0 5y agoExplain → -
ObjectOverloadingPOC ⑂
No description.
★ 0 4y agoExplain → -
HyperDeceit ⑂
HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system tasks with ease.
★ 0 3y agoExplain → -
CYBERSEC2023-BYOVD-Demo ⑂
No description.
★ 0 3y agoExplain → -
LLaMA-LoRA-Tuner ⑂
UI tool for fine-tuning and testing your own LoRA models with LLaMA. One-click run on Google Colab.
★ 0 3y agoExplain → -
PatchGuardBypass ⑂
Bypassing PatchGuard on modern x64 systems
★ 0 3y agoExplain → -
Kernel-Exploits ⑂
Kernel Exploits
★ 0 4y agoExplain → -
PPL_Sandboxer ⑂
No description.
★ 0 3y agoExplain → -
AmsiBypassHookManagedAPI ⑂
A new AMSI Bypass technique using .NET ALI Call Hooking.
★ 0 3y agoExplain → -
Kernel-Cactus ⑂
It's pointy and it hurts!
★ 0 3y agoExplain → -
HRSword ⑂
火绒剑独立版
★ 0 3y agoExplain → -
the-backdoor-factory ⑂
Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors
★ 0 4y agoExplain → -
Process-Magics ⑂
This is a collection of interesting codes about Windows Process creation.
★ 0 6y agoExplain → -
TelemetrySourcerer ⑂
Enumerate and disable common sources of telemetry used by AV/EDR.
★ 0 5y agoExplain → -
IDA2Obj ⑂
Static Binary Instrumentation
★ 0 4y agoExplain → -
SharpHandler ⑂
No description.
★ 0 5y agoExplain → -
ActiveDefense ⑂
小型主动防御引擎
★ 0 10y agoExplain → -
CVE-2021-40444 ⑂
CVE-2021-40444 PoC
★ 0 4y agoExplain → -
sgn ⑂
Shikata ga nai (仕方がない) encoder ported into go with several improvements
★ 0 5y agoExplain → -
simpleCoreCLRHost ⑂
This C++ app allows to run custom C# method from compiled C# .dll on Linux and OS X using coreCLR.
★ 0 5y agoExplain → -
macro_pack ⑂
macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for pentest, demo, and social engineering assessments. The goal of macro_pack is to simplify exploitation, antimalware bypass, and automatize the process from malicious macro and script generation to final document generation. It also provides a lot of helpful features useful for redteam or security research.
★ 0 5y agoExplain → -
Powershell-Obfuscator ⑂
Powerful script for logical obfuscation of powershell scripts
★ 0 7y agoExplain → -
VBAFunctionPointers ⑂
No description.
★ 0 5y agoExplain → -
amsiscanner ⑂
A C/C++ implementation of Microsoft's Antimalware Scan Interface
★ 0 8y agoExplain → -
loadlibrary ⑂
Porting Windows Dynamic Link Libraries to Linux
★ 0 5y agoExplain → -
UsoDllLoader ⑂
Windows - Weaponizing privileged file writes with the Update Session Orchestrator service
★ 0 6y agoExplain → -
ClrAnalyzer ⑂
.NET library for hooking and dumping Clr
★ 0 7y agoExplain → -
MegaDumper ⑂
Dump native and .NET assemblies
★ 0 7y agoExplain → -
TransactionMaster ⑂
A tool for Windows that can make any program work within file-system transactions.
★ 0 5y agoExplain → -
boobsnail ⑂
BoobSnail allows generating Excel 4.0 XLM macro. Its purpose is to support the RedTeam and BlueTeam in XLM macro generation.
★ 0 5y agoExplain → -
AMSI-Provider ⑂
A fake AMSI Provider which can be used for persistence.
★ 0 5y agoExplain → -
WindowsExploits ⑂
Windows exploits, mostly precompiled. Not being updated. Check https://github.com/SecWiki/windows-kernel-exploits instead.
★ 0 5y agoExplain → -
wowHijack ⑂
Run some secret code invisible from debugger single step.(x86 process on x64 windows only)
★ 0 6y agoExplain → -
EvasiveProcessHollowing ⑂
Evasive Process Hollowing Techniques
★ 0 5y agoExplain → -
injectopi ⑂
A set of tutorials about code injection for Windows.
★ 0 8y agoExplain → -
AllTheThings ⑂
Copy of Subtee's Repository That's Taken Down
★ 0 8y agoExplain →
No repos match these filters.