zha0's repositories

BamExtensionTableHook

Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when attackers disable standard process notify callbacks.

Stargazers:0Issues:0Issues:0

bin2shellcode

C++ tool and library for converting .bin files to shellcode in multiple output formats.

License:MITStargazers:0Issues:0Issues:0

BloodfangC2

Modern PIC implant for Windows (64 & 32 bit)

License:NOASSERTIONStargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

Chrome-App-Bound-Encryption-Decryption

Fully decrypt App-Bound Encrypted (ABE) cookies, passwords & payment methods from Chromium-based browsers (Chrome, Brave, Edge) - all in user mode, no admin rights required.

License:MITStargazers:0Issues:0Issues:0

Crystal-Loaders

A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike

License:GPL-3.0Stargazers:0Issues:0Issues:0

CVE-2025-25257

FortiWeb CVE-2025-25257 exploit

Stargazers:0Issues:0Issues:0

CVE-2025-32463_chwoot

sudo Local Privilege Escalation CVE-2025-32463

Stargazers:0Issues:0Issues:0

CVE-2025-47812-poc

Wing FTP Server Remote Code Execution (RCE) Exploit (CVE-2025-47812)

License:MITStargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

CVE-2025-53770

A sophisticated, wizard-driven Python exploit tool targeting CVE-2025-53770, a critical (CVSS 9.8) unauthenticated remote code execution (RCE) vulnerability in on-premises Microsoft SharePoint Server (2016, 2019, Subscription Edition)

Stargazers:0Issues:0Issues:0

CVE-2025-53770-Exploit

SharePoint WebPart Injection Exploit Tool

Stargazers:0Issues:0Issues:0

CVE-2025-5777

CVE-2025-5777 (CitrixBleed 2) - Critical memory leak vulnerability affecting Citrix NetScaler ADC and Gateway devices

Stargazers:0Issues:0Issues:0

dumping_lsass

The different ways to dump lsass

Stargazers:0Issues:0Issues:0

elfspirit

ELF static analysis and injection framework that parse, manipulate, patch and camouflage ELF files.

License:MITStargazers:0Issues:0Issues:0

Evanesco

Hide any window from screen capture on Windows.

License:GPL-3.0Stargazers:0Issues:0Issues:0

exploit-2

Exploits and advisories

Stargazers:0Issues:0Issues:0

GoldenDMSA

This tool exploits Golden DMSA attack against delegated Managed Service Accounts.

License:NOASSERTIONStargazers:0Issues:0Issues:0

InstagramPrivSniffer

Views Instagram private account's media without login

License:MITStargazers:0Issues:0Issues:0

intelligence

Malware, tooling, logs, IOCs and intelligence

Stargazers:0Issues:0Issues:0

Kanvas

A simple-to-use IR (incident response) case management tool for tracking and documenting investigations.

License:GPL-3.0Stargazers:0Issues:0Issues:0

MS-RPC-Fuzzer

Gain insights into MS-RPC implementations that may be vulnerable using an automated approach and make it easy to visualize the data. By following this approach, a security researcher will hopefully identify interesting RPC services in such a time that would take a manual approach significantly more.

License:Apache-2.0Stargazers:0Issues:0Issues:0

netescape

Malware traffic obfuscation library

License:MITStargazers:0Issues:0Issues:0
License:MITStargazers:0Issues:0Issues:0

OSEPlayground

A collection of useful tools and scripts were developed and gathered throughout the Offensive Security's PEN-300 (OSEP) course.

License:MITStargazers:0Issues:0Issues:0

rabbit.go

Bidirectional TCP tunnel written in go

License:MITStargazers:0Issues:0Issues:0

RiCharEpoint

SharePoint 2025 RCE Exploitation GUI

Stargazers:0Issues:0Issues:0

RingReaper

Simple Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

License:MITStargazers:0Issues:0Issues:0

RtlHijack

Alternative Read and Write primitives using Rtl* functions the unintended way.

License:MITStargazers:0Issues:0Issues:0

winver

Tiny Windows executable that outputs version information about the OS.

Stargazers:0Issues:0Issues:0