Thanks to visit codestin.com
Credit goes to github.com

Skip to content
View ybdt's full-sized avatar

Block or report ybdt

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

C 1,395 268 Updated Nov 22, 2023

Portable Executable parsing library (from PE-bear)

C++ 659 112 Updated Oct 4, 2025

https://0xrick.github.io/win-internals/pe8/

C++ 53 17 Updated Oct 29, 2021

A PowerShell variant of the amazing patch_review.py by kevthehermit

PowerShell 177 21 Updated Oct 23, 2025

Proof-of-Concept tool for extracting NTLMv1 hashes from sessions on modern Windows systems.

C 543 52 Updated Oct 27, 2025

Centralized resource for listing and organizing known injection techniques and POCs

669 74 Updated Dec 14, 2025

CPL remote trigger

Python 43 8 Updated Dec 28, 2025

Six Degrees of Domain Admin

Go 2,716 286 Updated Jan 28, 2026

A collection of various methods for adding user from windows

C 2 Updated Dec 23, 2025

Mimikatz implementation in pure Python

Python 3,239 415 Updated Jan 2, 2026

Extract SAM and SYSTEM using Volume Shadow Copy (VSS) API. With multiple exfiltration options and XOR obfuscation

C# 327 47 Updated Jan 13, 2026

Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form.

C++ 6,124 1,118 Updated Dec 15, 2025

BOF implementation of @_EthicalChaos_'s ThreadlessInject project. A novel process injection technique with no thread creation, released at BSides Cymru 2023.

C 394 56 Updated Jan 9, 2024

Threadless Process Injection using remote function hooking.

C# 806 89 Updated Sep 4, 2024

Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.

C# 4,452 755 Updated Jan 10, 2025

Shellcode and In-PowerShell solution for patching AMSI via Page Guard Exceptions

C++ 62 6 Updated Nov 15, 2025

BOF for Kerberos abuse (an implementation of some important features of the Rubeus).

C 534 66 Updated Nov 23, 2025

Trying to tame the three-headed dog.

C# 4,849 861 Updated Nov 14, 2025

🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

C 2,001 508 Updated Jul 13, 2022

免杀远控木马源码整理开源(银狐 winos 大灰狼 gh0st) Rat

C 668 306 Updated Nov 14, 2025

PC免杀远控winos4.0成品

29 9 Updated Mar 26, 2025

Mirror of the LuaJIT git repository

C 5,403 1,111 Updated Jan 9, 2026

A BOF that runs unmanaged PEs inline

C 677 84 Updated Oct 23, 2024

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

PowerShell 1,188 178 Updated Jan 22, 2026

A Visual Studio template used to create Cobalt Strike BOFs

C 323 55 Updated Nov 17, 2021

蓝队应急工具

YARA 541 53 Updated Jun 10, 2024

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

C++ 796 149 Updated Nov 1, 2025

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

Go 700 84 Updated Aug 26, 2025
Next