Skip to content
View S9MF's full-sized avatar

Block or report S9MF

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Modify machine code in binaries with alternative x64 assembly opcodes for AV evasion

Python 54 6 Updated Apr 16, 2026
PowerShell 119 13 Updated Apr 16, 2026

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

C 130 19 Updated Apr 15, 2026

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

Go 516 51 Updated Apr 19, 2026

Find zero-days while you sleep. DeepZero is an automated vulnerability research framework that parses, decompiles, and analyzes thousands of Windows kernel drivers for exploitable IOCTLs natively u…

Python 93 9 Updated Apr 16, 2026

Syscall BOF to arbitrarily add/detract process token privilege rights.

C 66 20 Updated Jul 10, 2024

EDR & AV Bypass Arsenal— a comprehensive collection of tools, patches, and techniques for evading modern EDR and antivirus defenses.

C 64 19 Updated Nov 17, 2025

Advanced shellcode loader with AES-256, EDR/AMSI/ETW bypass, indirect syscalls, evasion, early-bird APC injection and PPID spoofing.

C 28 9 Updated Apr 16, 2026

Modified versions of the Cobalt Strike Process Injection Kit

C 109 12 Updated Jan 24, 2024

A Cobalt Strike BOF implementation of the SilentHarvest registry dumping technique

C 138 12 Updated Apr 14, 2026

C++ version of the most known GodPotato

C++ 2 Updated Apr 2, 2026

BOF for Havoc that copies locked Windows files (SAM, SYSTEM, NTDS.dit) via raw MFT parsing — no VSS, no Registry APIs, no PowerShell

C 118 6 Updated Apr 6, 2026

Active Directory Vulnerability Scanner

Python 410 46 Updated Mar 3, 2026
C 125 21 Updated Dec 12, 2025

Robust Cobalt Strike shellcode loader with multiple advanced evasion features

C++ 204 28 Updated Apr 21, 2025

【JHeart 权限维持BOF】:一键扫描上线主机“白加黑”维权点

10 1 Updated Mar 26, 2026

Offensive security toolkit for Claude Code

Python 133 15 Updated Apr 1, 2026

COM-based DLL Surrogate Injection

C++ 167 18 Updated Dec 9, 2025

An example UDC2 implementation for CrystalC2.

C 17 2 Updated Mar 23, 2026

abusing windows toast notifications for fun and user manipulation

C 98 9 Updated Mar 20, 2026

A BOF to interact with COM objects associated with the Windows software firewall.

C++ 114 15 Updated Oct 10, 2021

Claude Code plugin for Java JAR security audit — 基于 jar-analyzer 的 Claude Code 安全审计插件,构建数据库,AI 深入分析

118 6 Updated Mar 20, 2026
C 198 30 Updated Mar 15, 2026

Cobalt Strike Aggressor Script for identifying security products on Windows hosts — six enumeration methods rated by noise level, from silent in-process BOF to full PowerShell/WMI.

C 44 4 Updated Feb 6, 2026

Automating the MITM attack on WSUS

Python 334 33 Updated Apr 3, 2026

NT AFD.sys file downloader (Windows 10/11 x64)

C++ 9 4 Updated Mar 18, 2026

代码审计工具

Python 10 Updated Apr 6, 2026
Next