Skip to content
View jiangdada6's full-sized avatar

Block or report jiangdada6

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
213 stars written in C
Clear filter

A little tool to play with Windows security

C 21,370 4,047 Updated May 11, 2025

Simple tool to configure Windows Filtering Platform (WFP) which can configure network activity on your computer.

C 8,218 609 Updated Mar 28, 2026

Defeating Windows User Account Control

C 7,462 1,418 Updated Feb 17, 2026

Kyanos is a networking analysis tool using eBPF. It can visualize the time packets spend in the kernel, capture requests/responses, makes troubleshooting more efficient.

C 5,001 228 Updated Mar 31, 2026

Dopamine is a semi-untethered jailbreak for iOS 15 and 16

C 4,841 6,022 Updated Mar 28, 2026

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters

C 4,517 736 Updated Jul 8, 2025

Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu, and KernelCTF. The success rate is 9…

C 2,439 333 Updated Apr 17, 2024

Open-Source Shellcode & PE Packer

C 2,085 331 Updated Feb 3, 2024

The swiss army knife of LSASS dumping

C 2,083 263 Updated Sep 17, 2024

🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

C 2,010 507 Updated Jul 13, 2022

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

C 1,839 240 Updated Nov 3, 2024

Situational Awareness commands implemented using Beacon Object Files

C 1,759 286 Updated Mar 10, 2026

Macro-header for compile-time C obfuscation (tcc, win x86/x64)

C 1,592 129 Updated Feb 14, 2026

LSASS memory dumper using direct system calls and API unhooking.

C 1,581 252 Updated Jan 5, 2021

Stealthy Linux Kernel Rootkit for modern kernels (6x)

C 1,551 173 Updated Mar 30, 2026

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens from Chrome, Edge, Brave & Avast - fileless, user-…

C 1,486 252 Updated Feb 9, 2026

Dump cookies and credentials directly from Chrome/Edge process memory

C 1,425 136 Updated Jan 19, 2026

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

C 1,404 270 Updated Nov 22, 2023

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

C 1,376 216 Updated Oct 27, 2023

Research code & papers from members of vx-underground.

C 1,365 255 Updated Dec 7, 2021

HVNC for Cobalt Strike

C 1,311 200 Updated Dec 7, 2023

A memory-based evasion technique which makes shellcode invisible from process start to end.

C 1,197 140 Updated Oct 16, 2023

A root exploit for CVE-2022-0847 (Dirty Pipe)

C 1,127 222 Updated Mar 8, 2022

C/C++ source obfuscator for antivirus bypass

C 1,066 191 Updated Mar 10, 2022

Cobalt Strike UDRL for memory scanner evasion.

C 1,008 179 Updated Jun 4, 2024

A protective and Low Level Shellcode Loader that defeats modern EDR systems.

C 916 144 Updated Mar 20, 2024

助力每一位RT队员,快速生成免杀木马

C 830 106 Updated Apr 17, 2024

Sleep Obfuscation

C 825 113 Updated Dec 3, 2023

A collection of my Semgrep rules to facilitate vulnerability research.

C 804 82 Updated Mar 30, 2026

Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a sacrificial Process as target process + (ACG+Bloc…

C 789 106 Updated Jan 26, 2026
Next