Thanks to visit codestin.com
Credit goes to github.com

Skip to content
View ljb200788's full-sized avatar

Block or report ljb200788

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

This application allows you to put various limits on Windows processes.

C# 731 70 Updated Oct 2, 2025

Adaptive DLL hijacking / dynamic export forwarding

C++ 795 135 Updated Jul 6, 2020

Adaptive DLL hijacking / dynamic export forwarding

C++ 2 1 Updated Jul 6, 2020

Enumerate and disable common sources of telemetry used by AV/EDR.

C++ 812 129 Updated Mar 11, 2021

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters

C 4,275 716 Updated Jul 8, 2025

An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer

C++ 522 78 Updated Feb 13, 2024

These are highly unstable, buggy, incomplete plugins that are not included with Process Hacker by default.

C 331 112 Updated Dec 21, 2021

OBS Studio - Free and open source software for live streaming and screen recording

C 67,695 8,753 Updated Oct 24, 2025

The C++ Core Guidelines are a set of tried-and-true guidelines, rules, and best practices about coding in C++

CSS 44,341 5,521 Updated Sep 29, 2025

etw hook (syscall/infinity hook) compatible with the latest Windows version of PG

C++ 290 83 Updated Apr 27, 2024

Pafish is a testing tool that uses different techniques to detect virtual machines and malware analysis environments in the same way that malware families do

C 3,799 490 Updated Jun 21, 2024

Crinkler is an executable file compressor (or rather, a compressing linker) for compressing small 32-bit Windows demoscene executables. As of 2020, it is the most widely used tool for compressing 1…

C++ 1,168 56 Updated Aug 4, 2022

PDB Downloader - An easier way to download Microsoft's public symbols for Libraries and Executables.

C# 299 81 Updated Mar 25, 2016

some gadgets about windows process and ready to use :)

C 608 98 Updated Oct 7, 2023

Sleep Obfuscation

C 796 110 Updated Dec 3, 2023

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

C++ 528 70 Updated Apr 8, 2025

Generic PE loader for fast prototyping evasion techniques

C 238 48 Updated Jul 2, 2024

Uses Threat-Intelligence ETW events to identify shellcode regions being hidden by fluctuating memory protections

C++ 147 14 Updated May 17, 2023

Walks the CFG bitmap to find previously executable but currently hidden shellcode regions

C++ 125 14 Updated May 17, 2023

shellcode生成框架

C++ 87 15 Updated Jul 11, 2024

无Windows API的新型恶意程序:自缺陷程序利用堆栈溢出的隐匿稳定攻击技术研究,A new type of malicious program without Windows API

C 87 18 Updated Mar 27, 2025

Portable Executable reversing tool with a friendly GUI

C++ 3,320 209 Updated Oct 25, 2025

Simple x86/x64 Assembler/Disassembler/Emulator

C++ 186 24 Updated Aug 1, 2024

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll , and trigger exported APIs from the export table

C++ 303 46 Updated Aug 2, 2023

An extensible framework for easily writing compiler optimized position independent x86 / x64 shellcode for windows platforms.

C++ 528 108 Updated Jul 2, 2025

A library to load, manipulate, dump PE files. See also: https://github.com/hasherezade/libpeconv_tpl

C++ 1,292 195 Updated May 25, 2025

Alternative Shellcode Execution Via Callbacks

C++ 1,642 320 Updated Nov 11, 2022

绕过卡巴斯基主动防御,加载驱动,unhook所有ssdt hook及shadow ssdt hook

C++ 38 30 Updated Sep 27, 2015

Sysark全称system anti-rootkit,是我学习内核写的工具(2013年的代码,后续不会再更新),里面基本上所有的功能都是用内核实现的。这里只是实现了反rootkit部分功能,作为工具的话,本人觉得还欠完善,但作为学习,或有人需要。目前针对的是XP SP2,对于其它版本的系统或者BSOD的问题,需要的人DIY一下。目前实现的功能: 进程/线程/模块、 驱动模块、 SSDT、 …

C++ 27 15 Updated Dec 26, 2017
Next