八〇六 (zha0gongz1)

zha0gongz1

Geek Repo

Company:Coder

Location:China

Github PK Tool:Github PK Tool

八〇六's starred repositories

goproxy

🔥 Proxy is a high performance HTTP(S) proxies, SOCKS5 proxies,WEBSOCKET, TCP, UDP proxy server implemented by golang. Now, it supports chain-style proxies,nat forwarding in different lan,TCP/UDP port forwarding, SSH forwarding.Proxy是golang实现的高性能http,https,websocket,tcp,socks5代理服务器,支持内网穿透,链式代理,通讯加密,智能HTTP,SOCKS5代理,黑白名单,限速,限流量,限连接数,跨平台,KCP支持,认证API。

Language:GoLicense:GPL-3.0Stargazers:15325Issues:443Issues:459

RedTeam-Tools

Tools and Techniques for Red Team / Penetration Testing

asm_book

A book teaching assembly language programming on the ARM 64 bit ISA. Along the way, good programming practices and insights into code development are offered which apply directly to higher level languages.

Language:AssemblyLicense:NOASSERTIONStargazers:2395Issues:33Issues:14

cpp-docs

C++ Documentation

Language:PowerShellLicense:CC-BY-4.0Stargazers:1409Issues:79Issues:0

AADInternals

AADInternals PowerShell module for administering Azure AD and Office 365

Language:PowerShellLicense:MITStargazers:1168Issues:33Issues:66

win32

Public mirror for win32-pr

Language:PowerShellLicense:CC-BY-4.0Stargazers:1017Issues:54Issues:0

steganography

Simple C++ Image Steganography tool to encrypt and hide files insde images using Least-Significant-Bit encoding.

Language:C++License:MITStargazers:968Issues:8Issues:4

ThreadStackSpoofer

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners and analysts.

Language:C++License:MITStargazers:959Issues:27Issues:1

ShellcodeFluctuation

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

Language:C++License:MITStargazers:858Issues:19Issues:3

FilelessPELoader

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

Language:C++License:MITStargazers:771Issues:11Issues:6

certsync

Dump NTDS with golden certificates and UnPAC the hash

Language:PythonLicense:MITStargazers:604Issues:3Issues:12

HWSyscalls

HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.

PipeViewer

A tool that shows detailed information about named pipes in Windows

Language:C#License:Apache-2.0Stargazers:535Issues:10Issues:1

windows-powershell-docs

This repo is used to contribute to Windows 10, Windows Server 2016, and MDOP PowerShell module documentation.

Language:PowerShellLicense:CC-BY-4.0Stargazers:431Issues:71Issues:1363

JNDInjector

一个高度可定制化的JNDI和Java反序列化利用工具

BofAllTheThings

Creating a repository with all public Beacon Object Files (BoFs)

sshd_backdoor

/root/.ssh/authorized_keys evil file watchdog with ebpf tracepoint hook.

RToolZ

A Stealthy Lsass Dumper - can abuse ProcExp152.sys driver to dump PPL Lsass, no dbghelp.lib calls.

Language:C#License:MITStargazers:286Issues:8Issues:0

NTDLLReflection

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll , and trigger exported APIs from the export table

Language:C++License:MITStargazers:285Issues:4Issues:2

CVE-2023-21608

Adobe Acrobat Reader - CVE-2023-21608 - Remote Code Execution Exploit

Language:JavaScriptLicense:GPL-3.0Stargazers:263Issues:5Issues:4

RpcInvestigator

Exploring RPC interfaces on Windows

Language:C#License:Apache-2.0Stargazers:245Issues:8Issues:30

serviceDetector

Detect whether a service is installed (blindly) and/or running (if exposing named pipes) on a remote machine without using local admin privileges.

findrpc

Idapython script to carve binary for internal RPC structures

Proxy-DLL-Loads

The code is a pingback to the Dark Vortex blog:

Language:CLicense:GPL-3.0Stargazers:156Issues:7Issues:0

CVE-2022-44666

Write-up for another forgotten Windows vulnerability (0day): Microsoft Windows Contacts (VCF/Contact/LDAP) syslink control href attribute escape, which was not fully fixed as CVE-2022-44666 in the patches released on December, 2022.

Language:Rich Text FormatLicense:Apache-2.0Stargazers:154Issues:6Issues:0

CreateRemoteThreadPlus

CreateRemoteThread: how to pass multiple parameters to the remote thread function without shellcode.

Language:CLicense:GPL-3.0Stargazers:120Issues:2Issues:0

Malproxy

Proxy system calls over an RPC channel

Language:C#Stargazers:96Issues:2Issues:0