Starred repositories
Analysis of CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) exploit chain - iOS Safari
Rust utilities for windows kernel debugging, reverse engineering and exploit development
Awesome AI Memory | LLM Memory | A curated knowledge base on AI memory for LLMs and agents, covering long-term memory, reasoning, retrieval, and memory-native system design. Awesome-AI-Memory 是一个 集…
Local persistent memory store for LLM applications including claude desktop, github copilot, codex, antigravity, etc.
100+ AI Agents, Agent Skills and RAG Apps - Free and Open Source.
MCP Server for Computer Use in Windows
Chrome MCP Server is a Chrome extension-based Model Context Protocol (MCP) server that exposes your Chrome browser functionality to AI assistants like Claude, enabling complex browser automation, c…
HotGo 是AI 赋能企业级全栈前后端分离开发及移动应用基础平台,基于 Vue 和 GoFrame2.0 构建;内置 AI 开发规范、适配主流 AI 开发工具,人机协同高效开发。集成 jwt 鉴权、动态路由菜单、casbin 鉴权、消息队列、定时任务等功能,预置各类常用场景文件,助力专注业务开发。
SysWhispers on Steroids - AV/EDR evasion via direct system calls.
Free universal database tool and SQL client
Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).
HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.
Anti-virus artifacts. Listing APIs hooked by: Avira, BitDefender, F-Secure, MalwareBytes, Norton, TrendMicro, and WebRoot.
Implementation of Advanced Module Stomping and Heap/Stack Encryption
Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes
KaynLdr is a Reflective Loader written in C/ASM
Stack Spoofing with Synthetic frames based on the work of namazso, SilentMoonWalk, and VulcanRaven
PoC Implementation of a fully dynamic call stack spoofer
A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!
Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners and analysts.
Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes, protect and elevate them with token manipulation.
different ntdll unhooking techniques : unhooking ntdll from disk, from KnownDlls, from suspended process, from remote server (fileless)