Skip to content
View M0chae1's full-sized avatar
🌴
On vacation
🌴
On vacation

Block or report M0chae1

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
55 stars written in C++
Clear filter

Fast C++ logging library.

C++ 28,558 5,094 Updated Mar 14, 2026

A simple C++11 Thread Pool implementation

C++ 8,717 2,352 Updated Jul 20, 2024

2021年最新整理, C++ 学习资料,含C++ 11 / 14 / 17 / 20 / 23 新特性、入门教程、推荐书籍、优质文章、学习笔记、教学视频等

C++ 6,260 1,249 Updated Jun 18, 2025

An even funnier way to disable windows defender. (through WSC api)

C++ 3,310 284 Updated Nov 23, 2025

Converts PE into a shellcode

C++ 2,751 468 Updated Aug 30, 2025

EDR Lab for Experimentation Purposes

C++ 1,428 151 Updated Mar 1, 2026

Remove AV/EDR Kernel ObRegisterCallbacks、CmRegisterCallback、MiniFilter Callback、PsSetCreateProcessNotifyRoutine Callback、PsSetCreateThreadNotifyRoutine Callback、PsSetLoadImageNotifyRoutine Callback...

C++ 1,299 222 Updated Jun 21, 2024

Now You See Me, Now You Don't

C++ 1,034 162 Updated Jan 23, 2026

Another Windows Local Privilege Escalation from Service Account to System

C++ 949 107 Updated Nov 12, 2022

Shoggoth: Asmjit Based Polymorphic Encryptor

C++ 782 99 Updated Apr 10, 2024

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

C++ 764 94 Updated Jan 26, 2025

Lifetime AMSI bypass

C++ 672 91 Updated Sep 26, 2023

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers, Unlinking .NET related modules, bypassing ETW+AMSI, avo…

C++ 595 113 Updated Jul 26, 2021

Shadow Dumper is a powerful tool used to dump LSASS memory, often needed in penetration testing and red teaming. It uses multiple advanced techniques to dump memory, allowing to access sensitive da…

C++ 572 91 Updated May 22, 2025

This is the tool to dump the LSASS process on modern Windows 11

C++ 569 66 Updated Nov 1, 2025

dump lsass进程工具

C++ 562 79 Updated Jul 20, 2023

A native backdoor module for Microsoft IIS (Internet Information Services)

C++ 555 129 Updated Jul 3, 2020

Windows Defender Killer | C++ Code Disabling Permanently Windows Defender using Registry Keys

C++ 500 70 Updated Jul 27, 2023

CPP AV/EDR Killer

C++ 480 73 Updated Nov 28, 2023

Bypassing UAC with SSPI Datagram Contexts

C++ 464 61 Updated Sep 24, 2023

从内存中提取浏览器和Todesk用户凭证

C++ 427 47 Updated Apr 13, 2025

Windows对抗沙箱和虚拟机的方法总结

C++ 402 37 Updated Apr 22, 2020

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

C++ 383 54 Updated Dec 13, 2024

AntiAV shellcode loader

C++ 331 73 Updated Nov 21, 2023

Netview enumerates systems using WinAPI calls

C++ 297 78 Updated Jan 30, 2022

汇总了目前可以找到的所有的进程注入的方式,完成了x86/x64下的测试,不断更新中

C++ 283 47 Updated Feb 8, 2022

Leak of any user's NetNTLM hash. Fixed in KB5040434

C++ 260 46 Updated Aug 13, 2024

A collection of proof-of-concept source code and scripts for executing remote commands over WinRM using the WSMan.Automation COM object

C++ 258 43 Updated May 12, 2020
Next