BOBO's repositories

COM-Hunter

COM Hijacking VOODOO

Language:C#License:MITStargazers:1Issues:0Issues:0

Blackhat-USA-2022-Materials

Presentation materials for my Black Hat USA 2022 Briefing and Arsenal talks

Stargazers:0Issues:0Issues:0

CallMeWin32kDriver

Load your driver like win32k.sys

License:MITStargazers:0Issues:0Issues:0
Language:C++Stargazers:0Issues:0Issues:0

Cronos-Rootkit

Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes, protect and elevate them with token manipulation.

Language:C++Stargazers:0Issues:0Issues:0
Language:CLicense:GPL-2.0Stargazers:0Issues:0Issues:0

CSAgent

CobaltStrike 4.x通用白嫖及汉化加载器

Stargazers:0Issues:0Issues:0

DCSec

域控安全one for all

Stargazers:0Issues:0Issues:0

DeathSleep

A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementing page protection changes during no execution.

Language:PythonStargazers:0Issues:0Issues:0

difuze

Fuzzer for Linux Kernel Drivers

Language:C++License:BSD-2-ClauseStargazers:0Issues:0Issues:0

Havoc

The Havoc Framework

License:GPL-3.0Stargazers:0Issues:0Issues:0

hollows_hunter

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).

Language:CLicense:BSD-2-ClauseStargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

katana

A next-generation crawling and spidering framework.

Language:GoLicense:MITStargazers:0Issues:0Issues:0

KernelCallbackTable-Injection

Code used in this post https://captmeelo.com/redteam/maldev/2022/04/21/kernelcallbacktable-injection.html

Language:CStargazers:0Issues:0Issues:0

KPPL

Kill Protected Process Light Process (include av)

Language:C++License:MITStargazers:0Issues:0Issues:0

llvm-msvc-build

Build llvm-msvc

License:GPL-3.0Stargazers:0Issues:0Issues:0

llvmanalyzer

笔者在一款基于LLVM编译器架构的retdec开源反编译器工具的基础上,融合了klee符号执行工具,通过符号执行(Symbolic Execution)引擎动态模拟反编译后的llvm的ir(中间指令集)运行源程序的方法,插桩所有的对x86指令集的thiscall类型函数对this指针结构体(也就是rcx寄存器,简称this结构)偏移量引用,经行分析汇总后自动识别this结构体的具体内容,并自动集成导入ida工具辅助分析.

License:NOASSERTIONStargazers:0Issues:0Issues:0

merlin

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

Language:GoLicense:GPL-3.0Stargazers:0Issues:0Issues:0

one-last-image

🧸「One Last Image」卢浮宫生成器 - One Last Kiss 封面风格生成器

Language:JavaScriptLicense:MITStargazers:0Issues:0Issues:0

open-vm-tools

Official repository of VMware open-vm-tools project

Language:CStargazers:0Issues:0Issues:0
Language:CLicense:MITStargazers:0Issues:0Issues:0

PDBRipper

PDBRipper is a utility for extract an information from PDB-files.

Language:CLicense:MITStargazers:0Issues:0Issues:0

PeNet

Portable Executable (PE) library written in .Net

Language:C#License:Apache-2.0Stargazers:0Issues:0Issues:0

rp

rp++ is a fast C++ ROP gadget finder for PE/ELF/Mach-O x86/x64/ARM/ARM64 binaries.

Language:C++License:MITStargazers:0Issues:0Issues:0
Language:C++License:MITStargazers:0Issues:0Issues:0

spring-spel-0day-poc

spring-cloud / spring-cloud-function,spring.cloud.function.routing-expression,RCE,0day,0-day,POC,EXP

Stargazers:0Issues:0Issues:0
Language:C++Stargazers:0Issues:0Issues:0

WeChatFerry

微信逆向。Hook WeChat, passing message between agent and WeChat.

Language:C++License:MITStargazers:0Issues:0Issues:0

windows-coerced-authentication-methods

A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various protocols.

Language:PythonStargazers:0Issues:0Issues:0