Senior Security Research Engineer @elastic. Former Red Team engineer. Passionate about cyber defence, security research, and systems programming.
Sanctum. Sanctum is an experimental proof-of-concept EDR, designed to detect modern malware techniques, above and beyond the capabilities of antivirus. Built in Rust.
567Wyrm. The dragon in the dark. A red team post exploitation framework for testing security controls during red team assessments.
511Hells-Hollow. Hells Hollow Windows 11 Rootkit technique to Hook the SSDT via Alt Syscalls
284Rust-Hells-Gate. Rust malware EDR evasion via direct syscalls, fully implemented as an example in Rust
90bloggr. A markdown compatible Golang blogging platform I use for my own blog
56ETW-Bypass-Rust. Event Tracing for Windows EDR bypass in Rust (usermode)
40BioNTdrv. Rust
31Vectored-Exception-Handling-Squared. Vectored Exception Handling Squared
30Scil. System Call Integrity Layer - experimental security research
28rust_shellcode. Pipeline for creating shellcode from a nostd rust project.
27Ferric-Fox. A windows 11 rootkit in Rust
19wdk-mutex. An idiomatic Rust mutex type for Windows kernel driver development.
15Rust-VBS-Enclave. Rust
15GoSneak. DLL injector POC written currently in C++ to be wrapped with Go and CGO.
13str_crypter. Str Crypter is a Rust macro to encrypt plaintext strings at compile time, and automatically decrypts them at runtime
10Rust-APC-Queue-Injection. APC Queue Injection EDR Evasion in Rust
9Basic-C-Reflective-DLL-Injector. A C based reflective DLL injector which will inject a DLL packed into the very same executable.
8ZestyChips. Re-engineering of a .net stealer using IMAP for c2
8Kernel-Fishing. A small Rust library with C interop for locating unexported/internal routines by byte pattern when no stable export exists.
8Rust-DLL-Search-Order-Hijacking. Rust DLL Search Order Hijacking
7velox. Velox is a work in progress, experimental Rust based Operating System written for fun and learning
7PE-Export-Resolver. Library to resolve function pointers to loaded modules in memory, such as functions provided by Windows DLL's
6maldev. ⚠️ malware development
6Rust-Remote-Process-DLL-Injection. Remote process DLL Injection in Rust
5CRTO-Notes. Certified Red Team Operator (CRTO) Cheatsheet and Checklist
5chx. Clipboard HexDumper is a command-line tool that allows you to read binary data of a file on disk, convert it to a hex dump or a base64 encoded string, and copy it to the clipboard.
4Simple-Rust-DLL. Rust
4Rust-Simple-DLL-Injector. Introduction to the Windows API for Rust, demonstrating a simple DLL injector
4SIMAP. A go based IMAP c2 server
3windows-drivers-rs. Platform that enables Windows driver development in Rust. Developed by Surface.
2ART-A-Radio-Telescope. Meet Art, he is A (simple) Radio Telescope. Art will be able to look into the galaxy and observe large hydrogen clouds undergoing quantum effects emitting radiation at a wavelength of approximatley 21 cm. Art will also measure the relative velocity of various parts of the Milky Way compared to the velocity of the Earth.
1wdk_mutex_tests. Rust
1