luom's starred repositories

Havoc

The Havoc Framework.

Language:GoLicense:GPL-3.0Stargazers:6372Issues:98Issues:319

auto-cpufreq

Automatic CPU speed & power optimizer for Linux

Language:PythonLicense:LGPL-3.0Stargazers:5399Issues:41Issues:426

EDR-Telemetry

This project aims to compare and evaluate the telemetry of various EDR products.

realm

A network relay tool

Language:RustLicense:MITStargazers:1443Issues:17Issues:113

dbxcli

A command line client for Dropbox built using the Go SDK

Language:GoLicense:NOASSERTIONStargazers:1040Issues:39Issues:139

RealBlindingEDR

Remove AV/EDR Kernel ObRegisterCallbacks、CmRegisterCallback、MiniFilter Callback、PsSetCreateProcessNotifyRoutine Callback、PsSetCreateThreadNotifyRoutine Callback、PsSetLoadImageNotifyRoutine Callback...

Language:C++License:MITStargazers:808Issues:18Issues:11

Pluto

Obfuscator based on LLVM 14.0.6

Language:LLVMLicense:MITStargazers:803Issues:28Issues:47

InlineExecute-Assembly

InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assembly execution as an alternative to Cobalt Strikes traditional fork and run execute-assembly module

Proxy-Attackchain

Proxylogon & Proxyshell & Proxyoracle & Proxytoken & All exchange server history vulns summarization :)

Language:C#Stargazers:482Issues:12Issues:0

.NetConfigLoader

.net config loader

Arkari

Yet another llvm based obfuscator based on goron.

Language:LLVMLicense:Apache-2.0Stargazers:294Issues:8Issues:9

SharpGmailC2

Our Friendly Gmail will act as Server and implant will exfiltrate data via smtp and will read commands from C2 (Gmail) via imap protocol

Language:C#License:MITStargazers:255Issues:10Issues:2

NVDrv

Abusing nvidia driver (nvoclock.sys) for physical/virtual memory and control register manipulation.

autochk-rootkit

Reverse engineered source code of the autochk rootkit

hw-call-stack

Use hardware breakpoints to spoof the call stack for both syscalls and API calls

Language:CLicense:MITStargazers:174Issues:4Issues:1

LoudSunRun

Stack Spoofing with Synthetic frames based on the work of namazso, SilentMoonWalk, and VulcanRaven

Cortex-XDR-Config-Extractor

Cortex XDR Config Extractor

Language:PythonLicense:GPL-3.0Stargazers:115Issues:4Issues:1

CVE-2023-27532

Exploit for CVE-2023-27532 against Veeam Backup & Replication

angryorchard

A kernel vulnerability used to achieve arbitrary read-write on Windows prior to July 2022

Language:CStargazers:102Issues:7Issues:0

ToyObfuscator

Toy LLVM obfuscator pass

Language:C++License:MITStargazers:70Issues:4Issues:2

ews-cpp

A C++11 header-only library for Microsoft Exchange Web Services

Language:C++License:Apache-2.0Stargazers:67Issues:12Issues:102

PsNotifRoutineUnloader

This script is used to unload PsSetCreateProcessNotifyRoutineEx, PsSetCreateProcessNotifyRoutine, PsSetLoadImageNotifyRoutine and PsSetCreateThreadNotifyRoutine from ESET Security to bypass the driver detection

Language:C++Stargazers:62Issues:3Issues:0

SuperCMD

Run program as SYSTEM, with TrustedInstaller token if desired

Language:C#License:GPL-2.0Stargazers:51Issues:3Issues:3

ShelbyObfuscator

Obfuscator for llvm 16.0.2

HookTools

Plugin for Process Hacker 2 ( https://github.com/processhacker2 ), displays system hooks and able to unhook too.