This is your work, valued
assembly_programming. This repo contains the things i learn about the assembly language through the course of time. Feel free to add something of your own to this.
★ 2Corsy. CORS Misconfiguration Scanner. This fork of CORS has additional features such as pipe through commandline and beautified errors
★ 2RandomPwn. These are some solutions of the 64-bit-binary-exploitation from various CTFs
★ 1Proof_of_Concept. This will contain all the proof of concepts i write for CVEs
★ 1gopher-os. A proof of concept OS kernel written in Go
★ 1Batman_Bugs. Python
★ 1Jatayu-SearchEngine. Jatayu is an open source federated search engine that respects your privacy and takes no personal data from your machine. The search engine is implemented using golang and elastic search. The search engine further employs a custom written crawler that crawlers all the links present on the given webpage/website, that can later be used to search through.
★ 1platform. The Open Binary Project full platform including OpenAPK.AI
★ 5decomp.me. Collaborative decompilation and reverse engineering website
★ 595theharbinger. Sane policies for insane agents
★ 7aixcc-afc-atlantis. C
★ 629NovaHypervisor. Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compatible with VMware and Hyper-V.
★ 269xserver. XLibre Xserver
★ 4.7kgopacker. UPX-like packer written in Go
★ 77Ekko. Sleep Obfuscation
★ 839Terminator. Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes
★ 1.1kFOLIAGE. Experiment on reproducing Obfuscate & Sleep
★ 167Cronos. PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.
★ 627ja4. JA4+ is a suite of network fingerprinting standards
★ 2kdocker2exe. Convert a Docker image to an executable
★ 2.2krmtrd. a kernel mode solution for detecting and prevent malicious threads creation in target process
★ 24SpacetimeDB. Development at the speed of light
★ 25ksiftrank. Use LLMs to rank anything
★ 188asm-lessons. FFmpeg Assembly Language Lessons
★ 12kSC-900. Study guide for the SC-900: Microsoft Security, Compliance, and Identity
★ 99vulnerable_linux_driver. An intentionally vulnerable linux driver for research purposes/practice in kernel exploit dev
★ 131waydroid. Waydroid uses a container-based approach to boot a full Android system on a regular GNU/Linux system like Ubuntu.
★ 12kThe-Art-of-Problem-Solving-in-Software-Engineering_How-to-Make-MySQL-Better. The Art of Problem-Solving in Software Engineering: How to Make MySQL Better
★ 1.9kDnsServer. Technitium DNS Server
★ 9.4kduck_chat. Reverse engineered DuckDuckGo AI chat API client.
★ 109hey. A DuckDuckGo AI chat client
★ 76fortios-auth-bypass-check-CVE-2024-55591. Python
★ 66pdfdoom. DOOM in a PDF (as ascii art)
★ 148cotp. Encrypted, command-line TOTP/HOTP authenticator app with import functionality.
★ 383paradedb. One Postgres for your application data, full-text search, vector retrieval, and aggregations. Home of the pg_search extension.
★ 9.1kInjector. Command line utility to inject and eject DLLs
★ 773Hunt-Sleeping-Beacons. Aims to identify sleeping beacons
★ 676markitdown. Python tool for converting files and office documents to Markdown.
★ 170kRustSoliloquy. A Rust implementation of Internal-Monologue — retrieving NetNTLM hashes without touching LSASS, leveraging SSPI for NTLM negotiation and indirect NTAPIs for core operations.
★ 193CVE-2024-48990-PoC. PoC for CVE-2024-48990
★ 104Hunting-Queries-Detection-Rules. KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
★ 1.7kCVE-2024-47176. Scanner
★ 9createdump. Leverage WindowsApp createdump tool to obtain an lsass dump
★ 151arancino. Arancino is a dynamic protection framework that defends Intel Pin against anti-instrumentation attacks.
★ 5binsider. Analyze ELF binaries like a boss 😼🕵️♂️
★ 4.4kedr-artifacts. This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.
★ 94semantic-grep. grep for words with similar meaning to the query
★ 1.2kIHxExec. Process injection alternative
★ 408dotfiles. Lua
★ 1.4kRed-Team-Infrastructure-Wiki. Wiki to collect Red Team infrastructure hardening resources
★ 4.5ktau. Fullstack Workspace for Humans & Machines
★ 5.1ktegon. Tegon is an open-source, dev-first alternative to Jira, Linear
★ 1.9kdashy. 🚀 A self-hostable personal dashboard built for you. Includes status-checking, widgets, themes, icon packs, a UI editor and tons more!
★ 26kvector. A high-performance observability data pipeline.
★ 22kForums-For-RFI. Data breaches, Leaks, Malwares Forums List <Please Use Vpn/TOR don't click on Link directly bad OPSEC>
★ 65diff-pdf. A simple tool for visually comparing two PDF files
★ 4.3kdocmost. Docmost is an open-source collaborative wiki and documentation software. It is an open-source alternative to Confluence and Notion.
★ 21ktriplit. A full-stack, syncing database that runs on both server and client. Pluggable storage (indexeddb, sqlite, durable objects), syncs over websockets, and works with your favorite framework (React, Solid, Vue, Svelte).
★ 3.1kreverser_ai. Provides automated reverse engineering assistance through the use of local large language models (LLMs) on consumer hardware.
★ 1.1keidos. An extensible framework for Personal Data Management.
★ 3.2kDumpert. LSASS memory dumper using direct system calls and API unhooking.
★ 1.6kInsightEngineering. Hardcore Debugging
★ 945dyninst. DyninstAPI: Tools for binary instrumentation, analysis, and modification.
★ 834HackSysExtremeVulnerableDriver. HackSys Extreme Vulnerable Driver (HEVD) - Windows & Linux
★ 3kC2-Tracker. Live Feed of C2 servers, tools, and botnets
★ 778worklenz. All in one project management tool for efficient teams
★ 3.1kquickemu. Quickly create and run optimised Windows, macOS and Linux virtual machines
★ 15kquary. Open-source BI for engineers
★ 2.4ktextbee. open-source sms-gateway. turn any android phone into an sms gateway
★ 3kllum. A fast, light, open chat UI with full tool use support across many models
★ 220nsh. The Noisy Sockets CLI
★ 265pcap-did-what. Analyze pcaps with Zeek and a Grafana Dashboard
★ 195pwntools. CTF framework and exploit development library
★ 14kopensecurity. opensecurity: open-source security and compliance. See and secure your cloud, containers, code, networks, deployments, devices. Define your rules, get precise checks, fix gaps fast. Streamlined audits. No fluff.
★ 716univer. Univer is a full-stack framework for creating and editing spreadsheets / word processor / presentation on both web and server.
★ 14ktypesense. Open Source alternative to Algolia + Pinecone and an Easier-to-Use alternative to ElasticSearch ⚡ 🔍 ✨ Fast, typo tolerant, in-memory fuzzy Search Engine for building delightful search experiences
★ 26kanime.gf. Local & Open Source Alternative to CharacterAI
★ 505nimfilt. A collection of modules and scripts to help with analyzing Nim binaries
★ 83tabby. Self-hosted AI coding assistant
★ 34klunatik. Lunatik is a framework for scripting the Linux kernel with Lua.
★ 591go-mtpfs. Mount MTP devices over FUSE
★ 721meilisearch. A lightning-fast search engine API bringing AI-powered hybrid search to your sites and applications.
★ 59kdesbordante-core. Desbordante is a high-performance data profiler that is capable of discovering many different patterns in data using various algorithms. It also allows to run data cleaning scenarios using these algorithms. Desbordante has a console version and an easy-to-use web application.
★ 492firecracker. Secure and fast microVMs for serverless computing.
★ 36kold-ada-mode. This is a fork of the old version of ada-mode.el that was distributed with Emacs.
★ 52opencti. Open Cyber Threat Intelligence Platform
★ 9.7klago. Open Source Metering and Usage Based Billing API ⭐️ Consumption tracking, Subscription management, Pricing iterations, Payment orchestration & Revenue analytics
★ 10kneko-rooms. Selfhosted collaborative browser - room management for n.eko
★ 747vercel. Develop. Preview. Ship.
★ 16kOpenFactVerification. Loki: Open-source solution designed to automate the process of verifying factuality
★ 1.2kemba. EMBA - The firmware security analyzer
★ 3.6kwireproxy. Wireguard client that exposes itself as a socks5 proxy
★ 5.7kduplex. Full duplex modern RPC
★ 391localtunnel. Expose localhost servers to the Internet
★ 3.2kxz-backdoor-documentation. Documentation about the xz backdoor created by #xz-backdoor-reversing
★ 60portr. Expose local http, tcp or websocket connections to the public internet
★ 3.1kheyform. Open-Source Form Builder
★ 8.9kxzbot. notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)
★ 3.6khollows_hunter. Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
★ 2.4krevng-c. C++
★ 419hunting-rules. Suricata rules for network anomaly detection
★ 182tracecat. Open-source security automation platform for teams and AI agents
★ 3.7kwirequery. WireQuery is the first full-stack session replay and API call exploration tool. Using WireQuery, you get a holistic overview of how an issue came into existence.
★ 307lapdev. Seamless dev environments for Kubernetes
★ 2kbcc. BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more
★ 23kmemories. Fast, modern and advanced photo management suite. Runs as a Nextcloud app.
★ 3.8kRETools. My reversing tools. Some custom, some not.
★ 214kubekit. kubernetes rootkit
★ 35neko. A self hosted virtual browser that runs in docker and uses WebRTC.
★ 22kBrowserBox. 💚🇺🇸🗽Secure remote browsing anywhere, any way you like it.
★ 3.9kputer. 🌐 The Internet Computer! Free, Open-Source, and Self-Hostable.
★ 43kEDR-Telemetry. This project aims to compare and evaluate the telemetry of various EDR products.
★ 2kiocextract. Defanged Indicator of Compromise (IOC) Extractor.
★ 583ohmyform. ✏️ Free open source alternative to TypeForm, TellForm, or Google Forms ⛺
★ 2.9kmitmproxy. An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
★ 45kstorm. Simple and powerful toolkit for BoltDB
★ 2.1kcoraza-traefik. Go
★ 23coraza-caddy. OWASP Coraza middleware for Caddy. It provides Web Application Firewall capabilities
★ 657coraza. OWASP Coraza WAF is a golang modsecurity compatible web application firewall library
★ 3.7kreor. Private & local AI personal knowledge management app for high entropy people.
★ 8.6kthunder. An open-source cross-platform Lemmy & PieFed client for iOS and Android
★ 1kZealOS. The Zeal Operating System is a modernized fork of the 64-bit Temple Operating System, TempleOS.
★ 2.4kNetExec. The Network Execution Tool
★ 5.7kgoph. 🤘 The native golang ssh client to execute your commands over ssh connection. 🚀🚀
★ 2kemail. Robust and flexible email library for Go
★ 2.8kawesome-startup. :sunglasses: All the required resources to build your own startup
★ 2.2khashmap.c. Hash map implementation in C.
★ 1ktwenty. The open alternative to Salesforce, designed for AI.
★ 54kPowerParse. PowerShell PE Parser
★ 63Jatayu-SearchEngine. Jatayu is an open source federated search engine that respects your privacy and takes no personal data from your machine. The search engine is implemented using golang and elastic search. The search engine further employs a custom written crawler that crawlers all the links present on the given webpage/website, that can later be used to search through.
★ 1tailadmin-free-tailwind-dashboard-template. Free and Open-source Tailwind CSS Dashboard Admin Template that comes with all essential dashboard UI components, pages and elements
★ 2.2kvti-dorks. Awesome VirusTotal Intelligence Search Queries
★ 334RedEye. RedEye is a visual analytic tool supporting Red & Blue Team operations
★ 2.8kschool-of-sre. At LinkedIn, we are using this curriculum for onboarding our entry-level talents into the SRE role.
★ 8.1kawesome-soc-analyst. Useful resources for SOC Analyst and SOC Analyst candidates.
★ 983Bochs. Bochs - Cross Platform x86 Emulator Project
★ 1.3kphnt. Native API header files for the System Informer project.
★ 1.5ksc. Common libraries and data structures for C.
★ 2.6ksecurity-research. This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.
★ 4.6kterraform-provider-esxi. Terraform-provider-esxi plugin
★ 568at-ps. Adversary Tactics - PowerShell Training
★ 1.6kbinsec. BINSEC binary-level open-source platform
★ 415universal-android-debloater. Cross-platform GUI written in Rust using ADB to debloat non-rooted android devices. Improve your privacy, the security and battery life of your device.
★ 20kmalwoverview. Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.
★ 4kHackSpaceCon_Malware_Analysis_Course. Free training course offered at Hack Space Con 2023
★ 138elevationstation. elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative
★ 386Run-in-Sandbox. Run PS1, VBS, CMD, EXE, MSI, Intunewin, MSIX, or extract ISO, ZIP in Windows Sandbox very quickly just from a right-click
★ 910signatures. Community Detection Signature Build and Distribution Pipeline for YARA, Suricata, Snort and Sigma
★ 27RendezvousRAT. Self-healing RAT utilizing libp2p
★ 88HeadlessBrowsers. A list of (almost) all headless web browsers in existence
★ 6.7kHackBrowserData. Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).
★ 14kQuick-Analysis. Quick analysis focusing on most important of a Malware or a Threat
★ 39WinPwn. Windows Pwnable Study
★ 426PyInstaLive. Python script to download Instagram livestreams.
★ 554EPI. Threadless Process Injection through entry point hijacking
★ 357AdGuardian-Term. 🛡️ Terminal-based, real-time traffic monitoring and statistics for your AdGuard Home instance
★ 1.6kjson.h. 🗄️ single header json parser for C and C++
★ 833GhidRust. GhidRust: Rust decompiler plugin for Ghidra
★ 376haproxy_ddos_protector. DDoS protection system PoC for HaProxy
★ 29Active-Directory-Pentest-Notes. 个人域渗透学习笔记
★ 1.8kpesieve-go. Golang bindings for PE-sieve
★ 43Confusables. Simple library for matching a string to another string that is same but has letters that only *look* the same as original string
★ 153sniffnet. Comfortably monitor your Internet traffic 🕵️♂️
★ 40kprogress. Linux tool to show progress for cp, mv, dd, ... (formerly known as cv)
★ 8.9kawesome-edr-bypass. Awesome EDR Bypass Resources For Ethical Hacking
★ 1.6kclfs-docs. Unofficial Common Log File System (CLFS) Documentation
★ 190CVE-2022-21894. baton drop (CVE-2022-21894): Secure Boot Security Feature Bypass Vulnerability
★ 352awesome-ebpf. A curated list of awesome projects related to eBPF.
★ 5.1kLOLBITS. ** DISCONTINUED ** C2 framework that uses Background Intelligent Transfer Service (BITS) as communication protocol and Direct Syscalls + Dinvoke for EDR user-mode hooking evasion.
★ 222Nidhogg. Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.
★ 2.4kMemProcFS. MemProcFS
★ 4.3kstrelka. Real-time, container-based file scanning at enterprise scale
★ 996acheron. indirect syscalls for AV/EDR evasion in Go assembly
★ 389Malware-Analysis.
★ 138PowerShell-Obfuscation-Bible. A collection of techniques, examples and a little bit of theory for manually obfuscating PowerShell scripts to achieve AV evasion, compiled for educational purposes. The contents of this repository are the result of personal research, including reading materials online and conducting trial-and-error attempts in labs and pentests.
★ 1.2kvbulletin-exploits. Exploits targeting vBulletin.
★ 75EDRs. C
★ 2.2kawesome-game-security. awesome game security [Welcome to PR]
★ 3.3kleptos. Build fast web applications with Rust.
★ 21kc.php. C to Python compiler in PHP
★ 299wanderer. An open-source process injection enumeration tool written in C#
★ 174format-corpus. An openly-licensed corpus of small example files, covering a wide range of formats and creation tools.
★ 208sok-dbi-security. Library to hide DBI artifacts when using Intel Pin. Code from the ASIA CCS 2019 paper "SoK: Using Dynamic Binary Instrumentation for Security (And How You May Get Caught Red Handed)"
★ 24diagrams. :art: Diagram as Code for prototyping cloud system architectures
★ 42kawesome-privacy. Awesome Privacy - A curated list of services and alternatives that respect your privacy because PRIVACY MATTERS.
★ 19kwails. Create beautiful applications using Go
★ 36kEfiGuard. Disable PatchGuard and Driver Signature Enforcement at boot time
★ 2.5kawesome-threat-detection. ✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
★ 4.7kmacOS-Simple-KVM. Tools to set up a quick macOS VM in QEMU, accelerated by KVM.
★ 14kosx-re-101. A collection of resources for OSX/iOS reverse engineering.
★ 1.7kpty. PTY interface for Go
★ 2.1ktiny_tracer. A Pin Tool for tracing API calls etc
★ 1.7kwitty. Web-based interactive terminal emulator that allows users to easily record, share, and replay console sessions.
★ 124webterm. web terminal based on xterm.js in rust
★ 56gotty. Share your terminal as a web application
★ 20kcloudshell. Xterm.js with a Go backend meant for use in containers
★ 149OffensiveRust. Rust Weaponization for Red Team Engagements.
★ 3kbluepill. BluePill: Neutralizing Anti-Analysis Behavior in Malware Dissection (Black Hat Europe 2019, IEEE TIFS 2020)
★ 130sshwifty. Web SSH & Telnet (WebSSH & WebTelnet client) 🔮
★ 3.1kRust. All Algorithms implemented in Rust
★ 26kdrltrace. Drltrace is a library calls tracer for Windows and Linux applications.
★ 419msticpy. Microsoft Threat Intelligence Security Tools
★ 2kPINdemonium. A pintool in order to unpack malware
★ 239Prompt-Engineering-Guide. 🐙 Guides, papers, lessons, notebooks and resources for prompt engineering, context engineering, RAG, and AI Agents.
★ 77kpe-sieve. Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).
★ 3.8kHover. A collection of CSS3 powered hover effects to be applied to links, buttons, logos, SVG, featured images and so on. Easily apply to your own elements, modify or just use for inspiration. Available in CSS, Sass, and LESS.
★ 29kHachi. This tool maps a file's behavior on MITRE ATT&CK matrix.
★ 60