Skip to content
View jwillyamz's full-sized avatar
🙊
🙃
🙊
🙃

Block or report jwillyamz

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

find dll base addresses without PEB WALK

Rust 169 21 Updated Jul 13, 2025

Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET assembli…

Zig 39 2 Updated Jun 2, 2026

Static devirtualizer for VMProtect 3.0-3.5. Lifts virtualized code to LLVM using Remill and strips the VM layer through optimization.

C++ 261 18 Updated Jun 2, 2026

POC Highlighting Obfuscation Techniques used by FIN threat actors based on cmd.exe's replace functionality and cmd.exe/powershell.exe's stdin command invocation capabilities

PowerShell 108 31 Updated Jul 2, 2017

Generate realistic synthetic security logs for cybersecurity threat hunting training and research

Python 125 11 Updated Jun 10, 2026

A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++

C 248 44 Updated Jun 11, 2026

Mach-O file structure

Python 13 Updated May 26, 2026

Distill intent. Surface failure modes. Keep the plan current.

Python 233 23 Updated Jun 15, 2026

A pytest-native safety and security testing framework for agentic AI applications

Python 358 42 Updated Jun 12, 2026

A small, fast, JavaScript-based JavaScript parser

JavaScript 11,400 1,035 Updated Jun 11, 2026

Recover and statically analyze manually-mapped DLLs whose PE headers are wiped at runtime. Pure-stdlib Python, no driver, no debugger required. Includes a Claude Code skill.

Python 10 1 Updated May 4, 2026
Python 5 Updated May 17, 2026

This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library

302 28 Updated May 24, 2026

Autonomous Windows POC developer from patchwatch diff reports

Python 45 9 Updated May 13, 2026

A local tool for ingesting Windows Patch Tuesday CVEs, diffing patched binaries with Ghidriff and surfacing LLM-generated security analysis through a browser UI

Rust 40 10 Updated May 19, 2026

Helping defenders learn and validate npm supply-chain detections with safe atomic tests.

PowerShell 34 3 Updated Oct 30, 2025

Browse and diff ETW provider snapshots across Windows builds. Backed by ETWInspector.

JavaScript 39 2 Updated Jun 12, 2026

LLVM based devirtualizer for the binaryshield software protector.

C++ 76 4 Updated May 7, 2026
C 4,838 775 Updated May 10, 2026

Shift Happens: Uncovering two built-in command injections in Windows context menus

10 1 Updated Mar 20, 2026

Polymorphic PE rewriter for Windows x64 , rewrites binaries into semantically identical but byte-different variants

C++ 185 32 Updated Jun 6, 2026

A curated list of Ransomware resources

41 1 Updated May 11, 2026

Proof of concept to show that Edge stores credentials in cleartext

C# 523 109 Updated Jun 10, 2026

Set of PoC to abuse Windows minifilters functionality

Rust 86 9 Updated May 1, 2026

IDA plugin for automatic deobfuscation of opaque predicates by lifting microcode to z3 for SMT reasoning.

Python 75 3 Updated Apr 30, 2026

Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code

Python 3,953 888 Updated Apr 29, 2026

Security audit tool for Claude Desktop and Claude Code on macOS — single-command visibility into MCP servers, extensions, plugins, connectors, scheduled tasks, and permissions.

PowerShell 293 48 Updated May 12, 2026
Next