Skip to content
View Ringx3's full-sized avatar

Block or report Ringx3

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

一款可以在不出网的环境下进行反向代理及cs上线的工具

Go 492 54 Updated Apr 26, 2023

Post-exploitation and evasion research toolkit for Linux.

C 265 31 Updated Jul 22, 2026

WebStrike 是一套以 Chromium 系浏览器扩展(Manifest V3) 为受控端点的指挥与控制(C2)套件。与传统以进程/驱动为主的 C2 相比,其工作重心落在 浏览器安全域:在合规授权与攻防演练场景下,可显著降低与终端 EDR 在 进程注入、驱动、内核回调 等层面的直接对抗成本,同时将能力锚定在用户 真实访问的 Web 会话 上。

Python 74 22 Updated Jul 8, 2026

MatouWebshell 是一款基于 Vue 3 和 Python 开发的开源 Webshell 管理与利用平台。支持高度自定义的流量伪装、内网穿透及内存马注入等功能。项目具有极高的扩展性,非常欢迎安全研究人员基于此开源架构进行二次开发(如自定义修改 Payload、新增混淆规则等)。

Python 23 2 Updated Apr 10, 2026

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support

Rust 242 29 Updated Feb 12, 2025

A Rust implementation of Internal-Monologue — retrieving NetNTLM hashes without touching LSASS, leveraging SSPI for NTLM negotiation and indirect NTAPIs for core operations.

Rust 193 20 Updated Apr 26, 2025

BOF to manage Active Directory Integrated DNS (ADIDNS)

C++ 28 3 Updated Jul 28, 2025

Reflective DLL loader.

C 26 7 Updated Jun 30, 2026

AdaptixFramework Extension Kit

C 550 146 Updated Apr 29, 2026

Versatile SOCKS5 proxying tool

Rust 17 2 Updated Jun 28, 2026

a minimal, position-independent C shellcode framework for Windows x64. compiles entirely on Linux

C 64 17 Updated Aug 1, 2026

Local privilege escalation via PetitPotam (Abusing impersonate privileges).

C 466 55 Updated Mar 30, 2023

Another Windows Local Privilege Escalation from Service Account to System

C++ 968 107 Updated Nov 12, 2022

Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability).

C# 830 130 Updated Dec 14, 2023

Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019

C# 1,837 234 Updated Sep 4, 2024

DCOM in memory and fileless lateral movement techniques through .Net deserilization

C# 284 33 Updated Jun 22, 2026

Windows 权限提升 BadPotato

C# 902 141 Updated May 10, 2020

Cobalt Strike Aggressor Script for identifying security products on Windows hosts — six enumeration methods rated by noise level, from silent in-process BOF to full PowerShell/WMI.

C 93 8 Updated Feb 6, 2026

BOF and research notes from hunting execution paths, covering Shell.HWEventHandlerShellExecute COM execution through the AutoPlay IHWEventHandler flow + ssh-shellhost.exe direct PTY command executi…

C 38 7 Updated Jun 20, 2026

A Beacon Object File (BOF) for Havoc/CS to Bypass PPL and Dump Lsass

C 178 22 Updated Sep 22, 2025

Lsass dumper evading (all ?) EDR detection

C 62 13 Updated Nov 10, 2025

Combining KslDump and GhostKatz to dump LSASS using no-fix KslD.sys memory read to bypass PPL. Extracts MSV1_0 NT hashes and WDigest cleartext passwords (if enabled) from LSASS using a Microsoft-si…

C++ 76 54 Updated Mar 25, 2026

PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping

Rust 36 4 Updated May 12, 2026

绕过PPL dump lsass内存

C++ 24 4 Updated Jul 6, 2026

Dump LSASS via physical memory read primitives in vulnerable kernel drivers

C 338 39 Updated Feb 2, 2026

first public in-process reflective PE loader for .NET NativeAOT binaries. maps a NativeAOT executable into the current process and executes it, bypassing the standard Windows loader.

C++ 28 5 Updated Mar 28, 2026
C 4,982 788 Updated May 10, 2026

Evasive loader for .NET Framework assemblies

C# 46 17 Updated May 14, 2026
Next