SymProcSleuth. A pure C version of SymProcAddress
29windows-ps-callbacks-experiments. Files for http://deniable.org/windows/windows-callbacks
25DllDragon. A simple to use single-include Windows API resolver
22Pandora-Hvnc-Hidden-Browser-Real-Vnc-Working-Chromium-Edge-Opera-Gx. Hidden Features Full Hidden Access Hidden Desktop Hidden Browsers Hidden Cmd Clone Profile Hidden PowerShell Hidden Explorer Hidden Startup Hidden Applications
20BSQLi-2.0. reverse engineered and improved BSQLi script from Coffinxp
14Attacker_Infrastructure_Setup. Shell
11RemoveNATfromWSL. Bridge your WSL instance onto to your network
11Valkyries-Embrace. Valkyrie's Embrace is a tool written in the Odin programming language that allows executing shellcode on a remote system.
9PrivilegeEscalationClass. C++ Privilege Escalation Class to execute Process As Admin from User and Process as NT AUTHORITY SYSTEM from Admin
7CaveCarver. CaveCarver - PE backdooring tool which utilizes and automates code cave technique
4Leaked-Credentials. how to look for Leaked Credentials !
4anti_injection. Prevents dll injection using SetProcessMitigationPolicy.
4Logsensor. A Powerful Sensor Tool to discover login panels, and POST Form SQLi Scanning
4FileExtractor. C++ Code to Extract Windows File and Receive in Linux Machine
4Null-AMSI. Null-AMSI is an AMSI and ETW bypass that takes advantage of .NET types (.NET Reflection) to bypassing AV/EDR.
3RDPCredentialStealer. RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++
3hidden. 🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc
3DumpLsass. C++ Code to perform a MiniDump of lsass.exe
3Admin2Sys. Admin2Sys it's a C++ malware to escalate privileges from Administrator account to NT AUTORITY SYSTEM
3HypercallPageHook. POC Hook of nt!HvcallCodeVa
3instagram-scraper. scrapes medias, likes, followers, tags and all metadata. Inspired by instagram-php-scraper
3AnonGT. Redirect All Traffic Through Tor Network
2emailGPT. a quick and easy interface to generate emails with ChatGPT
2val_crypt. compile-time encryption of values
2Proxll. Tool designed to simplify the generation of proxy DLLs while addressing common conflicts related to windows.h
2.NET_PROFILER_DLL_LOADING. .NET profiler DLL loading can be abused to make a legit .NET application load a malicious DLL using environment variables. This exploit is loading a malicious DLL using Task Scheduler (MMC) to bypass UAC and getting admin privileges.
2EchoStrike. Deploy undetectable reverse shells and perform stealthy process injection with EchoStrike – a Go-based tool for ethical hacking and Red Team operations.
2Phunter. Phunter is an osint tool allowing you to find various information via a phone number 🔎📞
2EDR-Freeze. EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.
2S4Uwhoami. Simple project shows how to use S4U2Self in Windows for making a "super whoami"
2reverse-shell-generator. Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)
2crewAI. Framework for orchestrating role-playing, autonomous AI agents. By fostering collaborative intelligence, CrewAI empowers agents to work together seamlessly, tackling complex tasks.
2bin2shellcode. C++ tool and library for converting .bin files to shellcode in multiple output formats.
2BaseEncoder. Multi Base Encoder, Encode in Base 16,32,64,85 with Replace and Reverse Features
2BackDoor-And-Listener. Python
2undetectableRevShell. This repo is for the youtube video where we have explained how to make a detectable reverse shell undetectable by windows defender
2sudo. It's sudo, for Windows
2Botnet. Python
2StealthAPCDispatcher. Thread scheduling stealth method using APC with encrypted shellcode
2bolt.new. Prompt, run, edit, and deploy full-stack web applications
2BrowserSnatcher. This project steals important data from all chromium and gecko browsers installed in the system and gather the data in a stealer db to be exfiltrated out.
2HackerGPT-2.0. TypeScript
2Custom-GetProcAddress. A custom implementation of GetProcAddress, often used in malware to evade detection by bypassing standard API resolution methods
2CallTrace. Simple Utility Tool To Trace System Calls Using Instrumention Callbacks.
2shadowcloak. Windows MTD-Based Ransomware Prevention using new extensions and file associations for files on choosen directories.
2Microsoft-Defender. Windows Security Center ISV Product Register
2memvid. Video-based AI memory library. Store millions of text chunks in MP4 files with lightning-fast semantic search. No database needed.
2Marble. The CIA's Marble Framework is designed to allow for flexible and easy-to-use obfuscation when developing tools.
2LibreChat. Enhanced ChatGPT Clone: Features OpenAI, GPT-4 Vision, Bing, Anthropic, OpenRouter, Google Gemini, AI model switching, message search, langchain, DALL-E-3, ChatGPT Plugins, OpenAI Functions, Secure Multi-User System, Presets, completely open-source for self-hosting. More features in development
2FullBypass. A tool which bypasses AMSI (AntiMalware Scan Interface) and PowerShell CLM (Constrained Language Mode) and gives you a FullLanguage PowerShell reverse shell. Feel free to DM if you find some bugs :)
2Jomungand. Shellcode Loader with memory evasion
2Sus-Domain-Monitor-CS-Blowout. Monitor all new suspicious domains from CS blowout
1PE_Image_Injector. 将当前进程的 PE Image (Sections) 注入到其他进程运行,实现进程迁移。Inject the PE Image (Sections) of the current process into other processes to achieve process injection.
1gelion-bypass. bypass for authentication i created which is an all in one hook.
1Syscall-Swapper. Simple project I made to swap over a syscall number from one function to another. Use freely just credit me...
1codecave-hook. codecave hook reverse engineering toolkit.
1OffsetsUpdater. A generic software to update dynamic memory locations using byte patterns.
1Chariot-Tackle. A small, easy to use API for making indirect syscalls locally.
1metamalloc. Single header template based general purpose memory allocation library for Linux & Windows. Repo also provides a live http memory profiler as a separate single-header with no dependencies
1Favicon_Recon. Search in shodan foe relted hosts with the same hash of the favicon of website
1