This is your work, valued
专注于红队实战攻防、二进制攻防、免杀、工具开发等原创内容分享
SearchAvailableExe. 寻找可利用的白文件
★ 563DllMainHijacking. Resolve the issue of DLLmain function in white and black DLLs hanging when calling shellcode
★ 208expandTextSection. A tool that expands the size of the text section in a PE file without loss, supporting both 32-bit and 64-bit programs.
★ 42Shellcode_Generator. IDA Python script for generating Windows x86 shellcode with one click
★ 41MultiTshProxy. tsh多终端代理通信
★ 21concurrency. 基于ants框架设计的网络请求并发模型
★ 17KillDriverProtect. 关闭恶意驱动的文件和注册表保护
★ 14FileMD5Check. 一款批量文件信誉或MD5查询工具,可以快速找出可疑文件和恶意文件。类似everything乞丐版工具
★ 5cs_stage_probe. 主动探测Cobalt Strike HTTP/HTTPS stager 入口并保存原始响应体
★ 5Neo-Maoku.
★ 3Attack. Research on Attack Technology
★ 2elf_to_shellcode. Convert any elf or command to shellcode
★ 2Rshell---A-Cross-Platform-C2. Rshell是一款开源的golang编写的支持多平台的C2框架,旨在帮助安服人员渗透测试、红蓝对抗。
★ 1Rshell-client. Rshell-client
★ 1gpt-5.6-instruct. A Codex jailbreak prompt and test pack for gpt-5.6-sol. 针对 gpt-5.6 系列的 Codex 破甲提示词与测试包。
★ 4.1kChrome-Browser-Stealer. Advanced Chrome v20 credential extractor (Chrome 127+). Extracts passwords from all profiles + cookies via lsass impersonation, DPAPI/CNG decryption. Exfiltrates ZIP to Discord. Authorized pentesting only.
★ 7WeChatDataAnalysis. 微信4.x数据解密并生成年度总结,高仿微信,实时更新,导出聊天记录,朋友圈,收藏等大量便捷功能
★ 1.9kdingwave. 钉钉数据库解密工具,支持 WEB UI 展示 | DingTalk Database Decryption Tool with Web UI Visualization.
★ 101dufs. A file server that supports static serving, uploading, searching, accessing control, webdav...
★ 11korca. Orca is the ADE for working with a fleet of parallel agents. Run any coding agent with your own subscription. Available on desktop, mobile and VPS.
★ 35kOperatorsKit. Collection of Beacon Object Files (BOF) for Cobalt Strike
★ 708Codex-X. Codex Switch & Instruct desktop manager
★ 1.9kKSword. [Windows toolkit for ARK] KSword 5.1 is an open-source Windows toolkit for ARK, kernel debugging, and system forensics. KSword 5.1 是面向 Windows 的开源 ARK、内核调试与系统取证工具集。
★ 307CS-EDR-Enumeration. Cobalt Strike Aggressor Script for identifying security products on Windows hosts — six enumeration methods rated by noise level, from silent in-process BOF to full PowerShell/WMI.
★ 92windows-defender-remover. A tool which is uses to remove Windows Defender in Windows 8.x, Windows 10 (every version) and Windows 11.
★ 8.1kwx_key. 获取微信4.0版本以上数据库密钥和图片密钥的工具 | A tool for obtaining database keys and image keys for WeChat versions 4.0 and above
★ 1.8kmcp-windbg. Model Context Protocol for WinDbg.
★ 1.5kWinKerDevBook1. Windows 系统安全:内核驱动开发
★ 143dnSpy.Extension.MCP. MCP extension for dnSpy.
★ 187wechatDownload. 微信公号文章下载工具
★ 1.2kwechat-article-to-markdown. 微信公众号文章抓取 & Markdown 转换工具
★ 969KDU. Kernel Driver Utility
★ 2.7kKslDump. KslDump — Why bring your own knife when Defender already left one in the kitchen?
★ 398SysWhispers4. AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64
★ 544windows-update-catalog-downloader. Windows Update Catalog Downloader
★ 2wxdown-service. 公众号文章下载网站 https://down.mptext.top 的增强服务
★ 151wechat-article-exporter. 一款在线的 微信公众号文章批量下载 工具,支持导出阅读量与评论数据,无需搭建任何环境,可通过 在线网站 使用,支持 docker 私有化部署和 Cloudflare 部署。 支持下载各种文件格式,其中 HTML 格式可100%还原文章排版与样式。
★ 13ksub2api. Sub2API 一站式开源中转服务,让 Claude、Openai 、Gemini、Grok订阅统一接入,支持拼车共享,更高效分摊成本,原生工具无缝使用。
★ 35kBYOVD. BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501).
★ 875UsingBYOVD. A C++ based BYOVD (Bring Your Own Vulnerable Driver) security research and testing project. It supports kernel-level operations including privilege escalation, physical memory R/W, and removing process protection via vulnerable drivers
★ 106code_review_agent. Go
★ 46Antivirus-Scan. What AV? 一款轻量级的杀软在线识别的项目,持续更新ing
★ 284knight-imagetopptx-skill. Semantic slide image to editable PPTX Codex skill
★ 84QDoctor. The first Computer Emergency Response (ARK) Tools for young people ;) 年轻人的第一款应急响应(ARK)工具 ;)
★ 682windows. Windows inside a Docker container.
★ 53kColdWer. Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass
★ 144CACM. Linux权限维持
★ 1.1kAV-EDR-Killer. AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)
★ 295CredsHunter. PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping
★ 31ppt-master. AI turns documents or topics into real, native PowerPoint decks—with native shapes, transitions and animations, data-backed charts and tables on demand, audio narration from speaker notes, and support for your own .pptx templates. · by Hugo He
★ 42kbinary_ninja_mcp. A Binary Ninja plugin containing an MCP server that enables seamless integration with your favorite LLM/MCP client.
★ 410ida-mcp-rs. Headless IDA Pro MCP Server
★ 680Tsec-Salon. 腾讯安全沙龙历届议题ppt,腾讯安全沙龙是由腾讯云鼎实验室主导运营的高端网络安全技术交流平台,是腾讯安全面向产学研各界打造的核心技术品牌之一。
★ 135Tsec-Hackathon. 腾讯云智能渗透黑客松 Official repository of Tencent Cloud Intelligent Penetration Hackathon. Showcasing top open-source projects of LLM-based autonomous penetration agents, including multi-agent collaboration, automated penetration, AI-driven offensive security, and intelligent attack-defense solutions.
★ 743chatgpt2api. ChatGPT官网接口纯协议的逆向实现,支持GPT-Image-2模型、文本模型,兼容OpenAI接口协议,在线批量生图/编辑图,号池管理,支持可编辑PPT/PSD文件逆向,支持导入CPA、sub2api号池 、支持接入Cherry Studio、New Api 等软件
★ 5.5ksuperpowers. An agentic skills framework & software development methodology that works.
★ 264kcodex-session-patcher. A lightweight Python tool to clean AI refusal responses from Codex CLI session files
★ 2.4kweb-access. 给 Claude Code 装上完整联网能力的 skill:三层通道调度 + 浏览器 CDP + 并行分治
★ 8.5kjava-chains. Java Vulnerability Exploitation Platform
★ 2.1kwaoowaoo. 首家工业级全流程 AI 影视生产平台。Industry-first professional AI Agent platform for controllable film & video production. From shorts to live-action with Hollywood-standard workflows.
★ 13kPPLrevenant. Bypass LSA protection using the BYODLL technique
★ 181Rikugan. A reverse-engineering agent for IDA Pro and Binary Ninja
★ 665garble. Obfuscate Go builds
★ 5.6kShell_Protect. VM一键加壳/脱壳,全压缩,反调试等
★ 360jar-obfuscator. Jar Obfuscator V2 - 一个 JAR 文件保护混淆工具,支持包名/类名/方法名/字段名/参数名引用分析和重命名混淆方式,支持字符串加密/整型异或混淆/垃圾代码花指令混淆/等方式,支持方法和字段的隐藏,支持 SpringBoot 和 war 包,配置简单,文档教程齐全,容易上手
★ 444APatch. The patching of Android kernel and Android system
★ 7.7keBPFDexDumper. eBPF-Based DexDumper for Android
★ 449oss-stinger. 利用oss实现http转发/cobalt strike上线
★ 370NETEMVocabulary. 考研词汇词频排序数据
★ 220opencode. The open source coding agent.
★ 192koh-my-openagent. omo/lazycodex: The coding agent for tokenmaxxers;the one and only agent harness for complex codebases. For your Codex, for your OpenCode
★ 67kAperant. Autonomous multi-session AI coding
★ 14kskills. This repository contains a collection of Agent Skills developed by GudaStudio, enabling seamless collaboration between Claude and other AI models and tools.
★ 2kvibe-kanban. Get 10X more out of Claude Code, Codex or any coding agent
★ 28kOpenSpec. Spec-driven development (SDD) for AI coding assistants.
★ 63kslidedeconstruct-ai. 针对当前 AI 生成 PPT 多为静态位图、难以二次编辑的痛点,本项目采用“识别+生成”双模型架构,实现了对静态演示文稿的深度重构与编辑。 SlideDeconstruct-AI 旨在让 AI 演示文稿从“一张死图”进化为真正可编辑、可交互的生产力工具。
★ 177wezterm-config. wezterm-config files
★ 277DAILA. A decompiler-agnostic plugin for interacting with AI in your decompiler. GPT-4, Claude, and local models supported!
★ 703goffloader. A Go implementation of Cobalt Strike style BOF/COFF loaders.
★ 285claude_codex_bridge. Visible multi-agent CLI workspace for mixing Codex, Claude, Gemini, Kimi, Qwen, Cursor, Copilot, Pi, OpenCode, and other AI coding agents
★ 3.3kcsbot. Golang Automation Framework for Cobalt Strike using the Rest API
★ 60chainlit. Build Conversational AI in minutes ⚡️
★ 12kgemini-3-pro-image-preview. Gemini 3 Pro - AI 绘图工作台 (Web Client)
★ 413next-ai-draw-io. A next.js web application that integrates AI capabilities with draw.io diagrams. This app allows you to create, modify, and enhance diagrams through natural language commands and AI-assisted visualization.
★ 34kbanana-slides. 一个基于nano banana pro🍌的原生AI PPT生成应用,迈向"Vibe PPT"; 支持上传任意模板图片,上传任意素材&智能解析,一句话/大纲/页面描述自动生成PPT,口头修改指定区域、一键导出可编辑ppt - An AI-native slides generator based on nano banana pro🍌
★ 15kRedInk. Red Ink - A one-stop Xiaohongshu image-and-text generator based on the 🍌Nano Banana Pro🍌, "One Sentence, One Image: Generate Xiaohongshu Text and Images."
★ 5.4kLKY_OfficeTools. 一键自动化 下载、安装、激活 Office 的利器。
★ 12kcode-switch. Claude Code & Codex 多供应商代理与管理工具
★ 829cc-switch. A cross-platform desktop All-in-One assistant for Claude Code, Codex, OpenCode, OpenClaw, Grok Build & Hermes Agent. Only official website: ccswitch.io
★ 123khello-agents. 📚 《从零开始构建智能体》——从零开始的智能体原理与实践教程
★ 70kHVNC. 基于Tinynuke修复得到的HVNC
★ 196KDemu. A Windows Kernel Driver Emulator base on Unicorn, Kernel Memory Dump and some of native environment
★ 185Beacon. 使用C简单重构Beacon,适配CobaltStrike客户端
★ 104Spark. ✨Spark is a web-based, cross-platform and full-featured Remote Administration Tool (RAT) written in Go that allows you control all your devices anywhere. Spark是一个Go编写的,网页UI、跨平台以及多功能的远程控制和监控工具,你可以随时随地监控和控制所有设备。
★ 2.4kRedGuard. RedGuard is a C2 front flow control tool,Can avoid Blue Teams,AVs,EDRs check.
★ 1.6kRshell---A-Cross-Platform-C2. Rshell是一款开源的golang编写的支持多平台的C2框架,旨在帮助安服人员渗透测试、红蓝对抗。
★ 533PackMyPayload. A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats. Supports: ZIP, 7zip, PDF, ISO, IMG, CAB, VHD, VHDX
★ 1.2kLOLDrivers. Living Off The Land Drivers
★ 1.7kBokuLoader. A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!
★ 1.4kNTR_loader. Loader Pre-Technology, Main thread hijacking without using API, get ntdll and kernel32 handle without peb. 加载器前置技术,不使用API进行主线程劫持,不使用PEB获取ntdll和kernel32的地址。
★ 94DockerHub. 2026年8月更新,目前国内可用Docker镜像源汇总,DockerHub国内镜像加速列表,🚀DockerHub镜像加速器
★ 9.4kC2. C2-下一代RAT
★ 521alioss-stinger. 利用阿里云oss对象存储,来转发http流量实现(cs)Cobalt Strike、msf 上线等 这之间利用阿里云的相关域名进行通信。
★ 170SharpHunter. Automated Hosting Information Hunting Tool - Windows 主机信息自动化狩猎工具
★ 555yara. The pattern matching swiss knife
★ 9.8kNoVmp. A static devirtualizer for VMProtect x64 3.x. powered by VTIL.
★ 2.2ksgn. SGN — polymorphic binary encoder
★ 2kchatlog. chat log tool, easily use your own chat data. 聊天记录工具,轻松使用自己的聊天数据
★ 9.2kawesome-mcp-servers. A collection of MCP servers.
★ 92kPoolParty. A set of fully-undetectable process injection techniques abusing Windows Thread Pools
★ 1.3kdefendnot. An even funnier way to disable windows defender. (through WSC api)
★ 3.6kVMAware. Advanced VM detection library and tool
★ 1.3kLoudSunRun. Stack Spoofing with Synthetic frames based on the work of namazso, SilentMoonWalk, and VulcanRaven
★ 270SilentMoonwalk. PoC Implementation of a fully dynamic call stack spoofer
★ 980AlternativeShellcodeExec. Alternative Shellcode Execution Via Callbacks
★ 1.7kcola_dnslog. Cola Dnslog v1.3.2 更加强大的dnslog平台/无回显漏洞探测辅助平台 完全开源 dnslog httplog ldaplog rmilog 支持dns http ldap rmi等协议 提供API调用方式便于与其他工具结合 支持钉钉机器人、Bark等提醒 支持docker一键部署 后端完全使用python实现 前端基于vue-element-admin二开
★ 501ida-pro-mcp. AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
★ 11kmoneta. Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs
★ 837anything-llm. Stop renting your intelligence. Own it with AnythingLLM. Everything you need for a powerful local-first agent experience
★ 64kpyinstxtractor. PyInstaller Extractor
★ 4.4klessmsi. A tool to view and extract the contents of an Windows Installer (.msi) file.
★ 1.7ksimplewall. Simple tool to configure Windows Filtering Platform (WFP) which can configure network activity on your computer.
★ 8.7kLECmd. Lnk Explorer Command line edition!!
★ 347llvm-project. The LLVM Project is a collection of modular and reusable compiler and toolchain technologies.
★ 40kSetIcon. Creates a windows icon file (.ico) from an image and sets it on an exe.
★ 42EDRs. C
★ 2.2kLoki. 🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications
★ 1.4kRevokeMsgPatcher. :trollface: A hex editor for WeChat/QQ/TIM - PC版微信/QQ/TIM防撤回补丁(我已经看到了,撤回也没用了)
★ 38kpy. 飘云ark(pyark)
★ 529MonitorControl. 🖥 Control your display's brightness & volume on your Mac as if it was a native Apple Display. Use Apple Keyboard keys or custom shortcuts. Shows the native macOS OSDs.
★ 34kWeChatTweak. A command-line tool for tweaking WeChat - 首款微信 macOS 客户端撤回拦截与多开 🔨
★ 14knanodump. The swiss army knife of LSASS dumping
★ 2.1kRmTools. 蓝队应急工具
★ 545VirtualKD-Redux. VirtualKD-Redux - A revival and modernization of VirtualKD
★ 977PPLKiller. Protected Processes Light Killer
★ 1kopenedr. Open EDR public repository
★ 2.7kCsgo-Full-kernel. csgo external running from kernelmode
★ 103kdmapper-1. 驱动加载器 -> 利用iqvw64e.sys映射驱动
★ 7DoH-ECH-Demo. 使用DoH + ECH实现的简单的Https和Websocket请求demo,可绕过GFW,用于研究流量隐藏技术
★ 128ObfuXtreme. ObfuXtreme is an advanced Python obfuscation tool for security research, reverse engineering education, and analysis of how obfuscation impacts static and signature-based detection.
★ 225CobaltStrikeDetected. 40行代码检测到大部分CobaltStrike的shellcode
★ 292ChatTTS-ui. 一个简单的本地网页界面,使用ChatTTS将文字合成为语音,同时支持对外提供API接口。A simple native web interface that uses ChatTTS to synthesize text into speech, along with support for external API interfaces.
★ 7.6kmd. ✍ WeChat Markdown Editor | 一款高度简洁的微信 Markdown 编辑器:支持 Markdown 语法、自定义主题样式、内容管理、多图床、AI 助手等特性
★ 13kMultiTshProxy. tsh多终端代理通信
★ 21F5-TTS. Official code for "F5-TTS: A Fairytaler that Fakes Fluent and Faithful Speech with Flow Matching"
★ 15kBlindEdr. A Blind EDR Project for Educational Purposes
★ 106Lamia-Syscall-Template. A generic x64 indirect syscall template for RED TEAM OPSEC
★ 12Spyndicapped. COM ViewLogger — new malware keylogging technique
★ 409kcp. :zap: KCP - A Fast and Reliable ARQ Protocol
★ 17ktelegram_info_export. 导出telegram信息到本地
★ 106hrtng. IDA Pro plugin with a rich set of features: decryption, deobfuscation, patching, lib code recognition and various pseudocode transformations
★ 1.9kAdobe-Downloader. macOS Adobe apps download & installer
★ 3.3kwhite_patch_detect. 通杀检测基于白文件patch黑代码的免杀技术的后门
★ 183Microsoft-Activation-Scripts. Open-source Windows and Office activator featuring HWID, Ohook, TSforge, and Online KMS activation methods, along with advanced troubleshooting.
★ 185kgdb-dashboard. Modular visual interface for GDB in Python
★ 12kshelf. Python library to convert elf to os-independent shellcodes
★ 62elf. small elf loader
★ 178loaders. Tiny loaders for various binary formats.
★ 246Supershell. Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell
★ 1.8kreverse_ssh. SSH based reverse shell
★ 1.4kReverseWidget. A lightweight GUI tool that implements some typical block cipher, coding, hashing, and multi-architecture assemble/disassembly framework, PE/AndroidAPP shell checker.
★ 2730dayMakeOS. 《30天自制操作系统》源码中文版。自己制作一个操作系统(OSASK)的过程
★ 6.4knt5src. Source code of Windows XP (NT5). Leaks are not from me. I just extracted the archive and cabinet files.
★ 1.4kShadowDumper. Shadow Dumper is a powerful tool used to dump LSASS memory, often needed in penetration testing and red teaming. It uses multiple advanced techniques to dump memory, allowing to access sensitive data in LSASS memory.
★ 586donut-decryptor. Retrieve inner payloads from Donut samples
★ 138CobaltStrike_OpenBeacon. Fully functional, from-scratch alternative to the Cobalt Strike Beacon (red teaming tool), offering transparency and flexibility for security professionals and enthusiasts.
★ 271mayfly-go. Browser-based management platform of machine, database (mysql pgsql oracle sqlserver Gauss sqlite), redis(standalone sentinel cluster), mongo, Es unified management and operation platform. (web版linux(终端 文件 脚本 进程)、数据库(mysql pgsql oracle sqlserver 高斯 达梦 sqlite)、数据同步、redis(单机 哨兵 集群)、mongo、Es统一管理操作平台)
★ 2.4kNimbo-C2. Nimbo-C2 is yet another (simple and lightweight) C2 framework
★ 445IOPaint. Image inpainting tool powered by SOTA AI Model. Remove any unwanted object, defect, people from your pictures or erase and replace(powered by stable diffusion) any thing on your pictures.
★ 23kComfyUI-Workflows-ZHO. 我的 ComfyUI 工作流合集 | My ComfyUI workflows collection
★ 7.7kPillager. Pillager是一个适用于后渗透期间的信息收集工具
★ 1.3kLaZagne. Credentials recovery project
★ 11ksearchall. 强大的敏感信息搜索工具
★ 994EDRPrison. Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry
★ 478RdpStrike. Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP.
★ 252HackBrowserData. Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).
★ 14kDetect-It-Easy. Program for determining types of files for Windows, Linux and MacOS.
★ 11kChromeKatz. Dump cookies and credentials directly from Chrome/Edge process memory
★ 1.5kLSTAR. LSTAR - CobaltStrike 综合后渗透插件
★ 1.3kexpandTextSection. A tool that expands the size of the text section in a PE file without loss, supporting both 32-bit and 64-bit programs.
★ 42Alcatraz. x64 binary obfuscator
★ 2kSupernova. Shellcode encryptor & obfuscator tool
★ 1kConferences. Conference presentation slides
★ 2.4kpystinger. Bypass firewall for traffic forwarding using webshell
★ 1.4kSearchAvailableExe. 寻找可利用的白文件
★ 563DllMainHijacking. Resolve the issue of DLLmain function in white and black DLLs hanging when calling shellcode
★ 208Banshee. Experimental Windows x64 Kernel Rootkit with anti-rootkit evasion features.
★ 612Maestro. Multilingual backdoor
★ 67SigFlip. SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.
★ 1.3kXiebroC2. 渗透测试C2、支持Lua插件扩展、域前置/CDN上线、自定义profile、前置sRDI、文件管理、进程管理、内存加载、截图、反向代理、分组管理
★ 1.4kCS-Situational-Awareness-BOF. Situational Awareness commands implemented using Beacon Object Files
★ 1.8klegba. The fastest and more comprehensive multiprotocol credentials bruteforcer / password sprayer and enumerator. 🥷
★ 1.9kBOF.NET. A .NET Runtime for Cobalt Strike's Beacon Object Files
★ 785RealBlindingEDR. Remove AV/EDR Kernel ObRegisterCallbacks、CmRegisterCallback、MiniFilter Callback、PsSetCreateProcessNotifyRoutine Callback、PsSetCreateThreadNotifyRoutine Callback、PsSetLoadImageNotifyRoutine Callback...
★ 1.3kraddebugger. A native, user-mode, multi-process, graphical debugger.
★ 7.3ktsh. Tiny SHell is an open-source UNIX backdoor.
★ 713PPLdump. Dump the memory of a PPL with a userland exploit
★ 893Dumpert. LSASS memory dumper using direct system calls and API unhooking.
★ 1.6kEDRSandblast. C
★ 1.8ktiny-AES-c. Small portable AES128/192/256 in C
★ 5kHEU_KMS_Activator.
★ 43kCoercedPotato. C
★ 235BestEdrOfTheMarket. EDR Lab for Experimentation Purposes
★ 1.5kInline-Execute-PE. Execute unmanaged Windows executables in CobaltStrike Beacons
★ 721ILSpy. .NET Decompiler with support for PDB generation, ReadyToRun, Metadata (&more) - cross-platform!
★ 26kavList. avList - 杀软进程对应杀软名称
★ 407javascript-obfuscator. A powerful obfuscator for JavaScript and Node.js
★ 16klink. link is a command and control framework written in rust
★ 579amber. Reflective PE packer.
★ 1.4kPhishingBook. 红蓝对抗:钓鱼演练资源汇总&备忘录
★ 1.2kself_delete_bof. BOF implementation of delete self poc that delete a locked executable or a currently running file from disk by its pid, path, or the current process.
★ 80adduserbysamr-bof. Cobalt Strike BOF that Add a user to localgroup by samr
★ 142PEASS-ng. PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
★ 20kutils. Tools of util
★ 1