This is your work, valued
The place where bunnies dwell, and bits become colossal
fibratus. Security sensor for realtime threat detection and protection
★ 2.5krabbitc. Micro container runtime
★ 188cubostratus. Blazingly fast Linux syscall collector
★ 76awesome-ctf. A curated list of CTF frameworks, libraries, resources and softwares
★ 10awesome-pentest. A collection of awesome penetration testing resources, tools and other shiny things
★ 8awesome-security. A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.
★ 7awesome-incident-response. A curated list of tools for incident response
★ 5netmutatus. Linux TCP/IP stack manipulation via Netlink / Netfilter
★ 5awesome-honeypots. an awesome list of honeypot resources
★ 3gobpf. Go bindings for creating BPF programs.
★ 3awesome-ebpf.
★ 2pe. A :zap: lightweight Go package to parse, analyze and extract metadata from Portable Executable (PE) binaries. Designed for malware analysis tasks and robust against PE malformations.
★ 2rabbitstack.github.io. RabbitStack blog
★ 2appscope. C
★ 1walk. Fast parallel version of golang filepath.Walk()
★ 1Custom-Fibratus-Rules. A few custom rules for the Fibratus tool (https://github.com/rabbitstack/fibratus)
★ 1compress. Optimized Go Compression Packages
★ 5.6kwin32k-callback-detouring. Abusing the win32k.sys kernel callback mechanism for arbitrary code execution
★ 106Kassandra. Reversed cassandra source code for educational purposes
★ 28gluegate. Memory API proxy via signed mozglue.dll
★ 40SukiUI. UI Theme for AvaloniaUI
★ 2.6kshad-ui. Avalonia-based UI Library inspired by shadcn and Suki UI Library
★ 523Avalonia. Develop Desktop, Embedded, Mobile and WebAssembly apps with C# and XAML. The future of .NET UI
★ 31kLACUNA-Chain. Six-layer call-stack spoofing via .pdata lacunae — defeats ETW-Ti, kernel callbacks, CET shadow stack, and return-address validation in a single composite chain.
★ 178RawHive. Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data straight from disk.
★ 88entropia. A compiled language for Windows position-independent x86-64 shellcode and Beacon Object Files.
★ 175AV-EDR-Killer. BYOVD PoC abusing the GoFly kernel driver to terminate protected processes from user mode via an unguarded IOCTL.Then Weaponize it to execute shell code
★ 3PhantomCtx. Activation Context Hijacking Evasion Tool
★ 304kassandra_x33fcon_2026. This repository contains the research tool presented at x33fcon 2026, along with the associated presentation slides. The content is made available for research and educational purposes.
★ 62duckdb. DuckDB is an analytical in-process SQL database management system
★ 40kduckdb-go. duckdb-go provides a database/sql driver for the DuckDB database engine.
★ 279LdrShuffle. Code execution/injection technique using DLL PEB module structure manipulation
★ 288Shelter. ROP-based sleep obfuscation to evade memory scanners
★ 388RustChain. Hide memory artifacts using ROP and hardware breakpoints.
★ 150apiwatcher. Standalone Windows API call tracer
★ 4rsigma. A complete Sigma detection engineering toolkit: parser, linter, evaluator, correlation engine, conversion framework, streaming daemon, MCP and LSP servers :crab:
★ 119cet-spoofing-detection. Stack spoofing Detection for CET processes by comparing shadow and user stacks.
★ 39DSCourier. DSCourier is a proof-of-concept that uses the WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries.
★ 210CustomRDI. Rewrite of Stephen Fewer's reflective DLL loader with djb2 hashing, indirect syscalls, forwarder handling, and per-section memory permissions
★ 7Fileless-Pe-Loader. A stealthy in-memory PE loader that downloads and executes Windows executables directly from RAM with ETW bypass, NTDLL unhooking. No disk writes, no traces.
★ 4Vectored-Overloading. Using Vectored Exception Handling and hardware breakpoint to hijack DLL loading
★ 4ruac. UAC bypass I wrote for Interium. Uses the CMSTP INF.
★ 7StackSentry. Windows memory scanner for call stack spoofing detection, unbacked shellcode, injected DLLs and in-memory C2 implants.
★ 37HellHall. Performing Indirect Clean Syscalls
★ 617GhostlyHollowingViaTamperedSyscalls2. Implementing Ghostly-Hollowing using tampered syscalls for remote PE injection
★ 75Tenebris-Gate. multi layer encryption for payloads with options of delivery welcome to the Tenebris side
★ 26Tenzo-X-DSI. Direct syscall DLL injector. Bypasses API hooks via Halo's Gate SSN recovery, RWX allocation, and manual PE mapping. Includes ETW patching, PEB debug flag clearing, and header wiping. Console UI with CLI support.
★ 10Monologue-Pwn. Steal Net-NTLMv1 hashes for logged on users without dumping LSASS
★ 15goodboy-framework. Learn Windows malware development and defense in Rust with 15 stages covering offense, detection, and AV testing
★ 4btype. B-tree based collection types for Go
★ 289SharpWMI. SharpWMI is a C# implementation of various WMI functionality.
★ 766SharpRDP. Remote Desktop Protocol .NET Console Application for Authenticated Command Execution
★ 1.2kNEBULA. Interactive PowerShell framework for testing WMI, COM, LOLBAS, and persistence techniques
★ 130AwesomeMalDevLinks. Awesome MalDev Links
★ 79DeadMatter. Offset Independent Credential Extraction Tool
★ 54DoppelGate. DoppelGate relies on reading ntdll on disk to grab syscall stubs, and patches these syscall stubs into desired functions to bypass Userland Hooking.
★ 125Probatorum-EDR-Userland-Hook-Checker. Project to check which Nt/Zw functions your local EDR is hooking
★ 202RightHand-Persistence. COM Windows Persistence Technique
★ 90vss-fr2system. test
★ 108RustPatchlessCLRLoader. .NET assembly loader with patchless AMSI and ETW bypass in Rust
★ 60HellsVectoredGate. C
★ 55PhantomRPC. C
★ 53superpowers. An agentic skills framework & software development methodology that works.
★ 264kPRTextractor. Go
★ 7trustme. BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation
★ 133AFInjector. Hides in your attic... I mean process
★ 24CustomLoadImage. Stealthy .NET assembly loading using AssemblyNative::LoadFromBuffer
★ 58owLSM. Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities
★ 280ECC. The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
★ 236kKaplaStrike. A Cobalt Strike RL built with Crystal Palac; module overloading, NtContinue entry transfer, call stack spoofing, sleep masking, and static signature removal.
★ 232PyrsistenceSniper. We took PersistenceSniper, merged it with Python, and misspelled it on purpose. Meet PyrsistenceSniper.
★ 242ThreadCPUAssignment_POC. A small experiment on assigning a processes threads a specific CPU and then blocking it with a high priority thread
★ 33lnk-it-up. Project for generating and identifying deceptive LNK files.
★ 375SysWhispers4. AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64
★ 544azazel. eBPF-powered silent observer for containerized runtimes, built for malware analysis sandboxes and Agentic AI monitoring.
★ 101claude-code-best-practice. from vibe coding to agentic engineering - practice makes claude perfect
★ 64kIoskeleyMono. Iosevka configuration to mimic the look and feel of Berkeley Mono as closely as possible.
★ 1.7kmarco. Inter-binary control flow graphing
★ 39lsa-whisperer. Tools for interacting with authentication packages using their individual message protocols
★ 438claude-code. Tips and tricks I use to optimize my experience with Claude Code.
★ 12AudioDG.exe-DLL-Hijacking-for-LPE. Audiodg.exe DLL hijacking for LPE with reboot-free restart primitive. Executes code as LOCAL SERVICE, escalates to SYSTEM via Scheduled Tasks.
★ 128Huginn. C++
★ 86chartdb. Database diagrams editor that allows you to visualize and design your DB with a single query.
★ 23krustinel. Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.
★ 445triager. Triage automation tool
★ 22awesome-maintainer-funding. A curated list of funding programs supporting the awesome work of Open Source maintainers.
★ 62design-patterns-for-humans. An ultra-simplified explanation to design patterns
★ 48kwarbird-demos. C++
★ 56dumping_lsass. The different ways to dump lsass
★ 289EventHorizon. Tool that gathers a customizable set of ETW telemetry and generates user-defined detections
★ 56DumpBrowserSecrets. Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from modern Chromium-based and Gecko-based browsers (Chrome, Microsoft Edge, Firefox, Opera, Opera GX, and Vivaldi)
★ 794BypassAV. This map lists the essential techniques to bypass anti-virus and EDR
★ 3.4kFilelessPELoader. Loading Remote AES Encrypted PE in memory , Decrypted it and run it
★ 1kThreatIntelligenceConsumer. Demonstrates consuming from a SecurityTrace ETW session by consuming from the Threat-Intelligence ETW provider without a driver or PPL privilege
★ 80Probabilistic-Call-Stack-PoC. A proof-of-concept to demonstrate randomized execution paths and their impact on call stack signatures — ideal for EDR testing, behavior-based detection research, and evasion analysis.
★ 24CallStackSpoof. Example of call stack spoofing trough the construction of syntetic frames and stack manipulation
★ 37psc. the ps utility, with an eBPF twist and container context
★ 298PoC. Various PoCs
★ 501cerberus. Know what's happening on your network before it becomes a problem: real-time eBPF monitoring
★ 69defender-acl-blocker. Block Windows Defender by deny ACL
★ 91getSPNless. Python tool to automatically perform SPN-less RBCD attacks.
★ 132notes. Full of public notes and Utilities
★ 135Proxy-DLL-Loads. A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.
★ 411EDR-GhostLocker. AppLocker-Based EDR Neutralization
★ 340DbgNexum. Shellcode injection using the Windows Debugging API
★ 183open-backup-ui. Community dashboard for monitoring supported platforms via REST APIs.
★ 25linux-sysops-handbook. Essentials of Linux system administration.
★ 836SpoolSample. PoC tool to coerce Windows hosts authenticate to other machines via the MS-RPRN RPC interface. This is possible via other protocols as well.
★ 1.1kDragonCastle. A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.
★ 306ntlm_theft. A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)
★ 1.5kPetitPotam. PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.
★ 2.3kSAMDump. Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. Implemented in C#, C++, Crystal and Python
★ 372DumpChromeSecrets. Extract data from modern Chrome versions, including refresh tokens, cookies, saved credentials, autofill data, browsing history, and bookmarks
★ 559CPLDCOMTrigger. Python
★ 47invisible-unicode-obfuscation-poc. HTML
★ 4ms-photos_NTLM_Leak. New 0 day vulnerability allowing to leak NTLM hashes from browsers with one click
★ 209