This is your work, valued
SilentMoonwalk. PoC Implementation of a fully dynamic call stack spoofer
★ 980nightmare. Python
★ 3.2kpoc-archive. A structured archive of Proof-of-Concept security research, organized by category with metadata, reproduction steps, and references.
★ 29HiveOracle. Raw NTFS volume oracle: locked-file read and offline SAM hashes without LSASS
★ 54publications. Publications from Calif
★ 686Offensive-COM. Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijacking, elevation of privilege, DCOM lateral movement, and persistence primitives with exploitation steps. Notes were generated by Kimi K3 Swarm may contain inaccuracies.
★ 135win32. Public mirror for win32-pr
★ 1.3kCVE-2026-54992-PoC. Proof of concept for CVE-2026-54992, an MSMQ remote-read integer overflow
★ 5Mindmap. This repository will contain many mindmaps for cyber security technologies, methodologies, courses, and certifications in a tree structure to give brief details about them
★ 9.2kHells-Hollow. Hells Hollow Windows 11 Rootkit technique to Hook the SSDT via Alt Syscalls
★ 284WindowsRootkitsGuide.
★ 85XeraLdr. A stealthy and modular Windows loader designed to bypass modern EDR solutions using Module Stomping, Stack Duplication, and Advanced Sleep Obfuscation.
★ 78CVE-2026-26128. PoC for exploiting CVE-2026-26128.
★ 62GhidraMCP. MCP Server for Ghidra
★ 9.7kbad-epoll.
★ 504win32k-callback-detouring. Abusing the win32k.sys kernel callback mechanism for arbitrary code execution
★ 106nocrt0. Custom C startup code for GCC/MinGW
★ 6InsideOLE. Companion code for Inside OLE 2nd Edition, published in 1995
★ 21darknet-mcp-server. 66-tool MCP server for dark web intelligence — breach data, ransomware tracking, Tor .onion access, malware analysis, blockchain intel, exploit search, stealer logs
★ 298BamExtensionTableHook. Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when attackers disable standard process notify callbacks.
★ 98Best-Books-for-Learning-Lisp-Programming. "Truth can only be found in one place: the code." ― Robert C. Martin
★ 16chrispe. ChirsPE is a experimental PE project built upon PEBakery's wim handling capabilities.
★ 49PseudoForge. An IDA Pro / Hex-Rays plugin that turns noisy pseudocode into reviewable, kernel-aware cleanup artifacts
★ 158