Skip to content
View ZephrFish's full-sized avatar
🌐
Building tools and tradecraft to help red and blue
🌐
Building tools and tradecraft to help red and blue

Organizations

@dc44141

Block or report ZephrFish

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results
C 1 Updated May 14, 2026

Direct Memory Access (DMA) Attack Software

C 7,658 999 Updated May 13, 2026
C 4,610 727 Updated May 10, 2026

Set of PoC to abuse Windows minifilters functionality

Rust 84 8 Updated May 1, 2026

Fully automatic censorship removal for language models

Python 21,000 2,167 Updated May 16, 2026

vanity address generator for tor onion v3 (ed25519) hidden services

C 1,586 174 Updated Feb 15, 2024

FaceDancer is an exploitation tool aimed at creating hijackable, proxy-based DLLs by taking advantage of COM-based system DLL image loading

Rust 435 53 Updated Apr 18, 2026

COM Windows Persistence Technique

C++ 82 12 Updated Apr 27, 2026

This is a novel technique that leverages the well-known Device Code phishing approach. It dynamically initiates the flow when the victim opens the phishing link and instantly redirects them to the …

Go 198 26 Updated Sep 19, 2025
Jupyter Notebook 12,893 955 Updated Oct 25, 2025

DSCourier is a proof-of-concept that uses the WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries.

PowerShell 186 22 Updated Apr 16, 2026

A modern runtime for JavaScript and TypeScript.

Rust 106,754 6,063 Updated May 17, 2026

A newly discovered vulnerable driver, pstrip64.sys (CVE-2026-29923) allows an unprivileged user to escalate privileges to SYSTEM via a crafted IOCTL request

C++ 21 2 Updated Apr 11, 2026

Windows Error Reporting ALPC Elevation of Privilege (CVE-2026-20817) - Proof-of-Concept exploit demonstrating local privilege escalation via WER service.

C++ 123 21 Updated Feb 19, 2026

An even funnier way to disable windows defender. (through WSC api)

C++ 3,423 292 Updated Nov 23, 2025

Repository hosting windows defender DOS tool

C++ 497 183 Updated Apr 12, 2026

Reattempt of BlueHammer disclosed in April 2026

C++ 48 16 Updated May 11, 2026

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

C 95 6 Updated Apr 9, 2026

Triageable Evidence Format

2 Updated Apr 9, 2026

AI-powered job search system built on Claude Code. 14 skill modes, Go dashboard, PDF generation, batch processing.

JavaScript 45,191 9,491 Updated May 17, 2026

Run frontier AI locally.

Python 44,751 3,168 Updated May 15, 2026

A BOF port of the research of @thefLinkk and @codewhitesec

C 103 18 Updated Oct 12, 2021
TypeScript 24 2 Updated Apr 21, 2026

20251127 Claude Code agentic assistants for identifying job market opportunities, evaluating them, and preparing for application

Python 5 1 Updated Nov 28, 2025

InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution

Python 147 9 Updated May 15, 2026

The first open-source harness builder for AI coding. Make AI coding deterministic and repeatable.

TypeScript 21,558 3,282 Updated May 17, 2026

Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Coba…

32 2 Updated Mar 28, 2026

Caddy as a reverse proxy for Docker

Go 4,475 216 Updated May 12, 2026
Next