shincehor's starred repositories

BruteUnpackage

Brute force cracking the compressed package | 暴力破解有密码的压缩包

Language:PythonStargazers:19Issues:0Issues:0

Jigsaw

Hide shellcode by shuffling bytes into a random array and reconstruct at runtime

Language:PythonStargazers:178Issues:0Issues:0

Shellcode-Hastur

Shellcode Reductio Entropy Tools

Stargazers:63Issues:0Issues:0

atexec-pro

Fileless atexec, no more need for port 445

Language:PythonStargazers:325Issues:0Issues:0

BackupCreds

A C# implementation of dumping credentials from Windows Credential Manager

Language:C#License:BSD-3-ClauseStargazers:56Issues:0Issues:0

Advanced-TLS-Injection

A direct improvement to remote TLS Injection.

Language:C++Stargazers:15Issues:0Issues:0

Thread-Pool-Injection-PoC

Proof of concept code for thread pool based process injection in Windows.

Language:C++Stargazers:105Issues:0Issues:0

Evasive-Loader

Evasive loader to bypass static detection

Language:CStargazers:54Issues:0Issues:0
Language:CLicense:MITStargazers:18Issues:0Issues:0

TrueSightKiller

CPP AV/EDR Killer

Language:C++Stargazers:355Issues:0Issues:0
Language:C#License:Apache-2.0Stargazers:1780Issues:0Issues:0

interactive-execute-shellcode

A simple PoC of injection shellcode into a remote process and get the output using namepipe

Language:C++License:UnlicenseStargazers:37Issues:0Issues:0

NtlmThief

Extracting NetNTLM without touching lsass.exe

Language:C++Stargazers:223Issues:0Issues:0

Artemis

Artemis - C++ Hell's Gate Syscall Implementation

Language:C++Stargazers:30Issues:0Issues:0
Language:RustStargazers:2Issues:0Issues:0

HackBrowserDataManual

Get password/cookie/history from browser and use devtools protocol to bypass edr monitoring

Language:GoStargazers:54Issues:0Issues:0

maldev-links

My collection of malware dev links

Stargazers:244Issues:0Issues:0

Killer

Killer tool is designed to bypass AV/EDR security tools using various evasive techniques.

Language:C++Stargazers:755Issues:0Issues:0

NinjaInjector

Classic Process Injection with Memory Evasion Techniques implemantation

Language:C++Stargazers:62Issues:0Issues:0
Language:C#Stargazers:312Issues:0Issues:0

RecycledGate

Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll

Language:CStargazers:444Issues:0Issues:0

BusySleepBeacon

This is a simple project made to evade https://github.com/thefLink/Hunt-Sleeping-Beacons by using a busy wait instead of beacon's built in Sleep() call. Most of the structure e.g. Sleep hook, shellcode exec etc. are taken from mgeeky's https://github.com/mgeeky/ShellcodeFluctuation.

Language:C++Stargazers:30Issues:0Issues:0

EPI

Threadless Process Injection through entry point hijacking

Language:RustLicense:NOASSERTIONStargazers:334Issues:0Issues:0

DKMC

DKMC - Dont kill my cat - Malicious payload evasion tool

Language:PythonLicense:NOASSERTIONStargazers:1377Issues:0Issues:0
Language:PythonStargazers:406Issues:0Issues:0

NacosRce

Nacos JRaft Hessian 反序列化 RCE 加载字节码 注入内存马 不出网利用

Language:JavaStargazers:739Issues:0Issues:0

Reverse-Engineering

A FREE comprehensive reverse engineering tutorial covering x86, x64, 32-bit/64-bit ARM and embedded RISC-V architectures.

Language:AssemblyLicense:Apache-2.0Stargazers:11211Issues:0Issues:0

ThreadlessInject-BOF

BOF implementation of @_EthicalChaos_'s ThreadlessInject project. A novel process injection technique with no thread creation, released at BSides Cymru 2023.

Language:CLicense:MITStargazers:367Issues:0Issues:0

KRBUACBypass

UAC Bypass By Abusing Kerberos Tickets

Language:C#Stargazers:480Issues:0Issues:0

DarkWidow

Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a sacrificial Process as target process + (ACG+BlockDll) mitigation policy on spawned process + PPID spoofing + Api resolving from TIB + API hashing

Language:CLicense:MITStargazers:556Issues:0Issues:0