Skip to content
View Swifto0's full-sized avatar
🌻
🌻

Block or report Swifto0

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
70 stars written in C
Clear filter

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

C 13,857 2,031 Updated Nov 6, 2025

A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware. Brought to you by Winsider Seminars & Solutions, Inc. @ http://www.windows-internals…

C 13,008 1,564 Updated Nov 5, 2025

Small and highly portable detection tests based on MITRE's ATT&CK.

C 11,179 2,992 Updated Nov 6, 2025

proxychains ng (new generation) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more socks/http proxies. continuation of the unmaintained p…

C 10,337 1,091 Updated Oct 18, 2025

This repo contains driver samples prepared for use with Microsoft Visual Studio and the Windows Driver Kit (WDK). It contains both Universal Windows Driver and desktop-only driver samples.

C 7,535 5,020 Updated Oct 17, 2025

UEFI firmware image viewer and editor

C 5,122 701 Updated Sep 26, 2025

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.

C 4,890 1,063 Updated Jan 22, 2025

eBPF implementation that runs on top of Windows

C 3,338 268 Updated Nov 6, 2025

🌴Linux、macOS、Windows Kernel privilege escalation vulnerability collection, with compilation environment, demo GIF map, vulnerability details, executable file (提权漏洞合集)

C 3,173 692 Updated Feb 15, 2023

Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a library from memory into a host process.

C 3,136 812 Updated Sep 3, 2022

Hiding kernel-driver for x86/x64.

C 2,527 459 Updated Sep 2, 2025

generate CobaltStrike's cross-platform payload

C 2,507 369 Updated Nov 20, 2023

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).

C 2,263 281 Updated Oct 31, 2025

BlackLotus UEFI Windows Bootkit

C 2,142 476 Updated Mar 28, 2024

The swiss army knife of LSASS dumping

C 2,022 256 Updated Sep 17, 2024

🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

C 1,969 502 Updated Jul 13, 2022

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

C 1,768 229 Updated Nov 3, 2024

Macro-header for compile-time C obfuscation (tcc, win x86/x64)

C 1,542 128 Updated Aug 4, 2025

A tool to kill antimalware protected processes

C 1,483 249 Updated Jun 19, 2021

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

C 1,370 263 Updated Nov 22, 2023

Dump cookies and credentials directly from Chrome/Edge process memory

C 1,359 128 Updated Sep 19, 2025

HVNC for Cobalt Strike

C 1,278 196 Updated Dec 7, 2023

A modern 32/64-bit position independent implant template

C 1,262 204 Updated Mar 21, 2025

A memory-based evasion technique which makes shellcode invisible from process start to end.

C 1,195 143 Updated Oct 16, 2023

Fully decrypt App-Bound Encrypted (ABE) cookies, passwords & payment methods from Chromium-based browsers (Chrome, Brave, Edge) - all in user mode, no admin rights required.

C 1,128 192 Updated Nov 6, 2025

Cobalt Strike UDRL for memory scanner evasion.

C 985 168 Updated Jun 4, 2024

Dump the memory of a PPL with a userland exploit

C 880 141 Updated Jul 24, 2022

Sleep Obfuscation

C 799 110 Updated Dec 3, 2023
Next