Skip to content
View ZephrFish's full-sized avatar
🌐
Building tools and tradecraft to help red and blue
🌐
Building tools and tradecraft to help red and blue

Organizations

@dc44141

Block or report ZephrFish

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Handful of Resources and Playbooks built as a result of our experience dealing with BEC Incidents

PowerShell 4 Updated Apr 1, 2026

The Artie the Owl badge for BSIDES Leeds 2026!

C++ 7 16 Updated Jun 6, 2026

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

C# 228 42 Updated Jun 13, 2026

WscApi Sample for C#, Use com to get Windows Security Center Products Details

C# 5 2 Updated Apr 4, 2018

Async PICO Hub is a work-in-progress framework to extend Cobalt Strike with custom event monitoring and in-process Asynchronous BOFs

C++ 9 2 Updated Jun 4, 2026

Proof-of-concept code for understanding the allow-jit entitlement on macOS

C++ 33 1 Updated Feb 19, 2026

Heimdal

C 367 199 Updated Jun 10, 2026

An 8-stage vulnerability-discovery agent.

Python 619 91 Updated Jun 10, 2026
C 1 Updated May 18, 2026

Direct Memory Access (DMA) Attack Software

C 7,733 1,004 Updated Jun 11, 2026
C 4,837 775 Updated May 10, 2026

Set of PoC to abuse Windows minifilters functionality

Rust 86 9 Updated May 1, 2026

Fully automatic censorship removal for language models

Python 24,554 2,631 Updated Jun 14, 2026

vanity address generator for tor onion v3 (ed25519) hidden services

C 1,595 175 Updated Feb 15, 2024

FaceDancer is an exploitation tool aimed at creating hijackable, proxy-based DLLs by taking advantage of COM-based system DLL image loading

Rust 440 53 Updated Apr 18, 2026

COM Windows Persistence Technique

C++ 86 11 Updated Apr 27, 2026

This is a novel technique that leverages the well-known Device Code phishing approach. It dynamically initiates the flow when the victim opens the phishing link and instantly redirects them to the …

Go 199 27 Updated Sep 19, 2025
Jupyter Notebook 12,967 954 Updated Oct 25, 2025

DSCourier is a proof-of-concept that uses the WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries.

PowerShell 199 23 Updated Apr 16, 2026

A modern runtime for JavaScript and TypeScript.

Rust 107,065 6,067 Updated Jun 14, 2026

A newly discovered vulnerable driver, pstrip64.sys (CVE-2026-29923) allows an unprivileged user to escalate privileges to SYSTEM via a crafted IOCTL request

C++ 23 3 Updated Apr 11, 2026

Windows Error Reporting ALPC Elevation of Privilege (CVE-2026-20817) - Proof-of-Concept exploit demonstrating local privilege escalation via WER service.

C++ 126 23 Updated Feb 19, 2026

An even funnier way to disable windows defender. (through WSC api)

C++ 3,503 291 Updated Nov 23, 2025

Reattempt of BlueHammer disclosed in April 2026

C++ 65 26 Updated May 11, 2026

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

C 97 7 Updated Apr 9, 2026

Triageable Evidence Format

2 Updated Apr 9, 2026

AI-powered job search system built on Claude Code. 14 skill modes, Go dashboard, PDF generation, batch processing.

JavaScript 53,669 10,682 Updated Jun 14, 2026

Run frontier AI locally.

Python 45,357 3,252 Updated Jun 14, 2026
Next