Taiwan

Sheng-Hao Ma

Elite
@aaaddress1

30cm.tw/me

RunPE-In-Memory. Run a Exe File (PE Module) in memory (like an Application Loader)

944

PR0CESS. some gadgets about windows process and ready to use :)

616

Skrull. Skrull is a malware DRM, that prevents Automatic Sample Submission by AV/EDR and Signature Scanning from Kernel. It generates launchers that can run malware on the victim using the Process Ghosting technique. Also, launchers are totally anti-copy and naturally broken when got submitted.

459

Windows-APT-Warfare. 著作《Windows APT Warfare:惡意程式前線戰術指南》各章節技術實作之原始碼內容

420

wowInjector. PoC: Exploit 32-bit Thread Snapshot of WOW64 to Take Over $RIP & Inject & Bypass Antivirus HIPS (HITB 2021)

163

my-Little-Ransomware. easy ransomware module base on csharp.

128

sakeInject. Windows PE - TLS (Thread Local Storage) Injector in C/C++

109

wowGrail. PoC: Rebuild A New Path Back to the Heaven's Gate (HITB 2021)

109

buyHouseAnalyzer. 開源台灣房市在線實價登錄分析工具

71

puzzCode. simple compiler based on mingw to build uncrackable windows application against analysis tools

62

wow64Jit. Call 32bit NtDLL API directly from WoW64 Layer

61

shellDev.py. tool for building windows shellcode in C by MinGW

54

theArk. Windows x86 PE Packer In C++

53

SignThief. Windows PE Signature Thief in C++

51

xlsKami. Out-of-the-Box Tool to Obfuscate Excel XLS. Include Obfuscation & Hide for Cell Labels & BoundSheets

47

vtMal. Malware Sandbox Emulation in Python @ HITCON 2018

46

ntkrnlProtectScan. One Click Tool to Scan All the Enabled Protection of current Windows NT Kernel

45

The-Purified-Elements. The Purified Windows 11: without Defender, Updater, Patches, System Health, etc.

45

xlsGen. (PoC) Tiny Excel BIFF8 Generator, to Embedded 4.0 Macros in xls files without Excel.

44

HellKitty-In-VC. Ring3 Rootkit Backdoor.

42

masqueradeCmdline. A PoC to demo modifying cmdline of the child process dynamically. It might be useful against process log tracing, AV or EDR.

40

madPocket. Play PokémonGo From Home, No Jailbreak!

38

dnLauncher. C

36

winInject101. Windows Injection 101: from Zero to ROP (HITCON 2017)

29

knownDlls_Poison. C

27

funcTracker. Useful Plugin for IDA to Trace Function Call Tree

26

Win-Exploit-Inject. PoC for DEF CON 26: Playing Malware Injection with Exploit thoughts

25

CrackShield-MapleStory-Hack. MapleStory Hack Plugin

25

Lexa. Windows Application Loader Running *.Exe files in Memory against Scrylla

21

APCInjector-BYPASS-AV. C++

19

isuMaster-NodeJS. 義守管家線上雲端服務

18

Whisper.py. 白癡喔還要下 pip install 誰會用啦—隨開即用 Windows 版 OpenAI Whisper 逐字稿產生器

17

PykemonGo. Play PokémonGo without hands, Based on Python, and Easy to fix.

15

moska. Tiny Windows x86 Assembly Compiler in C++ and Keystone Engine

14

goodGarena. Garena 競時通順暢開遊戲小補丁

13

WebBrowser-Control-GET-POST-Request-Hook-In-CSharp. Catch All HTTP Request In IE WebBrowser Control In C#

11

PowerCursor. Auto Move Your Cursor to the Focused Window while You Alt-Tab or Touchboard for Windows

10

OSX-Dyanmic-Hook. inline hook functions in memory on OSX

10

NTUSTxTDOH-Reversing-Game. NTUSTxTDOH 2015/11/15~29 Easy Crack Me

8

Chakra. Instagram 限時動態自動閱讀器

8

PkZIP-Unarchiver-in-C. Make stored PkZIP file unarchive in C

8

Algorithm. 一些演算法學習筆記

7

Win32-Debugger. 用CBuilder自幹Win32的除錯器.(搭配WinAPI)

7

easyChptchaOCR. 簡易義守選課驗證碼圖像100%辨識

7

vodka. .NET PE file parser in C/C++

6

Word2Vec.py. Word2Vec written in pure Numpy

6

engExamSystem-NodeJS. 基於 NodeJS 開發的英文克漏字線上測驗系統

6

BiuBiu. Control-Flow-Graph Analysis based on Radare2 In Python3

5

how-to-homework. C/C++ Dirty Work

5

Dad-sRoot. Easy Process Spy For Windows7 x32bit

5

IconJector. Unorthodox and stealthy way to inject a DLL into the explorer using icons

4

praHeapSpray. Heap Spray Practice

4

m00d1e.js. Get important information of moodle in node.js

4

C-CodingStyleHacker-In-CSharp. C#

4

NTUSTXTDOH_EasyBofBasic. 2015/12/27 台科BOF基礎講課Live Demo程式

4

FkBBTalk. 剃除該死的聊聊

3

googMeow. Google Search Ninja based on Python

3

capa. The FLARE team's open-source tool to identify capabilities in executable files.

3

defendnot. An even funnier way to disable windows defender. (through WSC api)

2

dc30-space-jam. Resources and demos from the DEFCON 30 Brief "Space Jam: Exploring Radio Frequency Attacks in Outer Space" by James Pavur

2
60
Apply