Starred repositories
A PoC for Mhyprot2.sys vulnerable driver that allowing read/write memory in kernel/user via unprivileged user process.
Amazing, fast & easy to use discord token stealer.
A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vanity-a-new-approach-to-code-injection--edr-bypass…
Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made w…
Bootkit for Windows Sandbox to disable DSE/PatchGuard.
Client/server code that impersonates TLS 1.3 to disguise C2 activity.
Run executables from memory, over the network, on Windows, Linux, OpenVMS... routers... spaceships... toasters etc.
Abuse the node.js inspector mechanism in order to force any node.js/electron/v8 based process to execute arbitrary javascript code.
Kernel Security driver used to block past, current and future process injection techniques on Windows Operating System.
SystemGap - Maintenance Tools after privilege escalation
Project for identifying executables and DLLs vulnerable to environment-variable based DLL hijacking.
A modern, portable, easy to use crypto library.
Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard
Multi-threaded, multi-os/platform (Linux/Windows) c2 server and Windows reverse TCP shell client both written in C.
PHP shells that work on Linux OS, macOS, and Windows OS.
WebRTC/RTSP/RTMP/HTTP/HLS/HTTP-FLV/WebSocket-FLV/HTTP-TS/HTTP-fMP4/WebSocket-TS/WebSocket-fMP4/GB28181/SRT/STUN/TURN server and client framework based on C++11
Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.
Porting Windows Dynamic Link Libraries to Linux
Collection of DLL function export forwards for DLL export function proxying
A small library helping to parse commandline parameters (for C/C++)
libfv is C++20 header-only network library, support TCP/SSL/Http/websocket server and client