Skip to content
View jamarir's full-sized avatar
🎲
!deraeppa ̷̤̱̐.̴͍̈Ỏ̸͚͈͙N̷̯̿̑͊Ģ̸̲͊Ņ̸̹̉͌̇I̶͚̝̍͘S̷̗̼̓̄̐Ş̸͐̃Į̶̙͇͌̏M dliW
🎲
!deraeppa ̷̤̱̐.̴͍̈Ỏ̸͚͈͙N̷̯̿̑͊Ģ̸̲͊Ņ̸̹̉͌̇I̶͚̝̍͘S̷̗̼̓̄̐Ş̸͐̃Į̶̙͇͌̏M dliW

Block or report jamarir

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

Malware

29 repositories

A repository of code signing certificates known to have been leaked or stolen, then abused by threat actors

YARA 411 27 Updated Apr 3, 2024

This repository contains sample programs that mimick behavior found in real-world malware. The goal is to provide source code that can be compiled and used for learning purposes, without having to …

C 697 86 Updated Jul 6, 2024

Conti Locker source code

C++ 196 94 Updated Mar 2, 2022

My collection of malware dev links

Python 317 34 Updated Feb 9, 2026

Defund the Police.

13,862 2,668 Updated Jun 7, 2024

Collection of malware source code for a variety of platforms in an array of different programming languages.

Assembly 18,412 2,071 Updated May 30, 2026

Small portable AES128/192/256 in C

C 4,967 1,392 Updated Oct 4, 2024

Intel.AES-NI: Leveraging Intel AES-NI for AES-128 & AES-256 Encryption Modes

C 25 1 Updated Jun 10, 2025

transform your payload into ipv4/ipv6/mac arrays

C 256 38 Updated Aug 18, 2022

The following two code samples can be used to understand the difference between direct syscalls and indirect syscalls

C 243 25 Updated Jan 20, 2024

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters

C 4,627 742 Updated Jul 8, 2025

PowerShell Obfuscator

PowerShell 4,270 809 Updated Aug 10, 2023

A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end to end.

YARA 1,463 165 Updated May 5, 2026

Curated resources for malware dev, reverse engineering, and defensive security research.

1,747 194 Updated Apr 1, 2026

The FLARE team's open-source tool to identify capabilities in executable files.

Python 6,059 703 Updated Jun 15, 2026

Extract data from modern Chrome versions, including refresh tokens, cookies, saved credentials, autofill data, browsing history, and bookmarks

C 556 78 Updated Jan 8, 2026

Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from modern Chromium-based and Gecko-based browsers …

C 740 111 Updated May 31, 2026

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

C 761 108 Updated May 23, 2025

Ransomware simulator written in Golang

Go 481 58 Updated Jun 30, 2022

Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.

C# 1,525 165 Updated Mar 17, 2026

Process Hollowing (Malware Technique)

C++ 1,378 227 Updated Oct 1, 2025

A not so awesome list of malware gems for aspiring malware analysts

830 142 Updated Feb 7, 2023

免杀姿势学习、记录、复现。

C++ 808 148 Updated Jul 10, 2022

PSAmsi is a tool for auditing and defeating AMSI signatures.

PowerShell 398 71 Updated Apr 22, 2018

A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware. Brought to you by Winsider Seminars & Solutions, Inc. @ https://windows-internals.com

C 14,986 1,709 Updated Jun 16, 2026

Simple executable generator with encrypted shellcode.

C# 281 69 Updated Oct 3, 2022

The Red Sun vulnerability repository

C++ 2,208 507 Updated Apr 15, 2026