Lists (26)
Sort Name ascending (A-Z)
aigc/llm
archive
bootkit
codec
compiler/script/obfus/lift
cpp
debugger
edr/ids
emu/dbi/hook
evm
exp
forensic/detect/scan
hypervisor
ida
🫨meme
🤯mind blowing
📰news
poc/demo
ref
Signing
smm
Todo
tools
tricks
visualization
watermark
Starred repositories
A set of tools to retrieve and parse TCG measured boot logs. Microsoft refers to these as Windows Boot Confirguration Logs (WBCL). In order to retrieve these logs, you must be running at least Wind…
Simple EFI runtime driver that hooks GetVariable function and returns data expected by Windows to make it think that it's running with secure boot enabled (faking secure boot)
A collection of 100+ specialized Claude Code subagents covering a wide range of development use cases
Debug native Windows code - C and C++ programs, services, and even the Windows kernel - straight from Visual Studio Code, using the same engine that powers WinDbg.
Native deterministic requirements-as-code engine and read-only MCP server.
A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if hand…
Fast Rust port of Steve Yegge's beads: local-first, non-invasive issue tracker storing tasks in SQLite with JSONL export for git collaboration
CVE-2026-0047: Missing permission check in ActivityManagerService.dumpBitmapsProto() — steal UI bitmaps from every running app with zero permissions (Android 16 QPR2 Beta)
The Interception API aims to build a portable programming interface that allows one to intercept and control a range of input devices.
Windows kernel-mode reboot-restore driver — NTFS volume filter with copy-on-write redirection
Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.
A WinDbg plugin that turns the current debugging session into an MCP server for command docs, debugger actions, and AI-assisted analysis.
Il2CppDumper fork with a native Rust PDB generator for x64 PE (GameAssembly.dll): function names, full struct types and typed prototypes, auto-loaded by IDA.
Static devirtualizer for VMProtect 3.0-3.5. Lifts virtualized code to LLVM using Remill and strips the VM layer through optimization.
An IDA Pro / Hex-Rays plugin that turns noisy pseudocode into reviewable, kernel-aware cleanup artifacts
UEFI SMM payload mapper with hot reload for on-hardware development
A collection of various vulnerable (mostly physical memory exposing) drivers.
Unofficial ChatGPT desktop app for Linux (formerly the Codex app), built locally from OpenAI’s official macOS app. Includes Chat, Work, and Codex. Packages for Debian/Ubuntu (.deb), Fedora/openSUSE…
Usermode exploit to bypass any AC using a 0day shatter attack.
POC project to demonstrate how to make a process (or a thread) critical. If such process (or thread) is terminated, this will cause a BSOD.
Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.
debug isolated usermode process on Nested Virtualization guest vm
Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.
Reverse of MSI's MAG X670E TOMAHAWK WIFI bios v1KB (2026-03-20) which claims "Implemented the anti-cheat mechanism" in the release notes.