Skip to content
View dunderhay's full-sized avatar

Organizations

@TeamWalrus

Block or report dunderhay

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Windows Defender 0day vulnerability

C++ 523 165 Updated Aug 11, 2026

Cobalt Strike Beacon Object File to enable the webdav client service on x64 windows hosts

C 27 2 Updated Sep 15, 2023

Extract hashes from VBK files -- cause it's fun...

Python 40 4 Updated Aug 10, 2026

Pass-the-Passkey Family of Attacks

C# 179 18 Updated Jul 22, 2026

POC tool for ResetNightmare (CVE-2026-27912)

PowerShell 192 33 Updated Aug 2, 2026

Passkeys/FIDO2/WebAuthn .NET Library for Windows Desktop and CLI Applications

C# 56 10 Updated Jun 19, 2026

Python collector for adding SCCM attack paths to BloodHound with OpenGraph

Python 138 4 Updated Aug 9, 2026

Certighost POC

Python 312 77 Updated Jul 28, 2026

Encrypted shellcode Injection to avoid Kernel triggered memory scans

C 429 46 Updated Sep 12, 2023

A Python library for extracting structured information from unstructured text using LLMs with precise source grounding and interactive visualization.

Python 38,368 2,689 Updated Aug 11, 2026

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and staging location for shellcode injection into remote …

C 206 23 Updated Jul 8, 2026

PoC for exploiting CVE-2026-26128.

Python 62 8 Updated May 6, 2026

Abusing the win32k.sys kernel callback mechanism for arbitrary code execution

C 117 14 Updated Apr 10, 2026

Shadow Dumper is a powerful tool used to dump LSASS memory, often needed in penetration testing and red teaming. It uses multiple advanced techniques to dump memory, allowing to access sensitive da…

C++ 589 90 Updated May 22, 2025

iOS/macOS Research Swiss Army Knife

Go 3,634 299 Updated Aug 14, 2026

Beacon Object File to Enable Chrome DevTools Protocol (CDP)

Python 120 10 Updated Aug 4, 2026

Cobalt Strike Aggressor Script for identifying security products on Windows hosts — six enumeration methods rated by noise level, from silent in-process BOF to full PowerShell/WMI.

C 93 8 Updated Feb 6, 2026

A compiled language for Windows position-independent x86-64 shellcode and Beacon Object Files.

C 179 19 Updated Jun 28, 2026

Beacon Object Files (BOFs) for Cobalt Strike and Havoc C2. Implementations of Active Directory attacks and post-exploitation techniques.

C 118 10 Updated Jan 26, 2026

Havoc BOF implementation of BYOVD attack to terminate PPL-protected EDR processes using a signed Microsoft kernel driver.

C 40 14 Updated Apr 6, 2026

Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin resolution experiments

C 88 12 Updated Jun 20, 2026

A credential extraction .NET assembly for Veeam Backup & Replication and Veeam One

C# 30 2 Updated May 14, 2026

PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping

Rust 36 4 Updated May 12, 2026

GreatXML bitlocker bypass vulnerability

626 247 Updated Jun 11, 2026

DCOM in memory and fileless lateral movement techniques through .Net deserilization

C# 282 33 Updated Jun 22, 2026

RoguePlanet Windows Defender Vulnerability

C++ 1,599 614 Updated Jun 9, 2026

Performing Indirect Clean Syscalls

C 623 80 Updated May 2, 2026
Next