North West, England

Ian G

Elite
@0xflux

Senior Security Research Engineer @elastic. Former Red Team engineer. Passionate about cyber defence, security research, and systems programming.

Sanctum. Sanctum is an experimental proof-of-concept EDR, designed to detect modern malware techniques, above and beyond the capabilities of antivirus. Built in Rust.

567

Wyrm. The dragon in the dark. A red team post exploitation framework for testing security controls during red team assessments.

511

Hells-Hollow. Hells Hollow Windows 11 Rootkit technique to Hook the SSDT via Alt Syscalls

284

Rust-Hells-Gate. Rust malware EDR evasion via direct syscalls, fully implemented as an example in Rust

90

bloggr. A markdown compatible Golang blogging platform I use for my own blog

56

ETW-Bypass-Rust. Event Tracing for Windows EDR bypass in Rust (usermode)

40

BioNTdrv. Rust

31

Vectored-Exception-Handling-Squared. Vectored Exception Handling Squared

30

Scil. System Call Integrity Layer - experimental security research

28

rust_shellcode. Pipeline for creating shellcode from a nostd rust project.

27

Ferric-Fox. A windows 11 rootkit in Rust

19

wdk-mutex. An idiomatic Rust mutex type for Windows kernel driver development.

15

Rust-VBS-Enclave. Rust

15

GoSneak. DLL injector POC written currently in C++ to be wrapped with Go and CGO.

13

str_crypter. Str Crypter is a Rust macro to encrypt plaintext strings at compile time, and automatically decrypts them at runtime

10

Rust-APC-Queue-Injection. APC Queue Injection EDR Evasion in Rust

9

Basic-C-Reflective-DLL-Injector. A C based reflective DLL injector which will inject a DLL packed into the very same executable.

8

ZestyChips. Re-engineering of a .net stealer using IMAP for c2

8

Kernel-Fishing. A small Rust library with C interop for locating unexported/internal routines by byte pattern when no stable export exists.

8

Rust-DLL-Search-Order-Hijacking. Rust DLL Search Order Hijacking

7

velox. Velox is a work in progress, experimental Rust based Operating System written for fun and learning

7

PE-Export-Resolver. Library to resolve function pointers to loaded modules in memory, such as functions provided by Windows DLL's

6

maldev. ⚠️ malware development

6

Rust-Remote-Process-DLL-Injection. Remote process DLL Injection in Rust

5

CRTO-Notes. Certified Red Team Operator (CRTO) Cheatsheet and Checklist

5

chx. Clipboard HexDumper is a command-line tool that allows you to read binary data of a file on disk, convert it to a hex dump or a base64 encoded string, and copy it to the clipboard.

4

Simple-Rust-DLL. Rust

4

Rust-Simple-DLL-Injector. Introduction to the Windows API for Rust, demonstrating a simple DLL injector

4

SIMAP. A go based IMAP c2 server

3

windows-drivers-rs. Platform that enables Windows driver development in Rust. Developed by Surface.

2

ART-A-Radio-Telescope. Meet Art, he is A (simple) Radio Telescope. Art will be able to look into the galaxy and observe large hydrogen clouds undergoing quantum effects emitting radiation at a wavelength of approximatley 21 cm. Art will also measure the relative velocity of various parts of the Milky Way compared to the velocity of the Earth.

1

wdk_mutex_tests. Rust

1
32
Apply