Skip to content
View SecStarBot's full-sized avatar

Block or report SecStarBot

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
123 stars written in C
Clear filter

My implementation of enSilo's Process Doppelganging (PE injection technique)

C 629 119 Updated Aug 30, 2022

Red-Team Linux kernel rootkit

C 598 86 Updated Oct 27, 2025

绕3环的shellcode免杀框架

C 574 155 Updated Mar 19, 2021

Syscall免杀

C 511 57 Updated Jun 21, 2024

Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North Korean APT InkySquid / ScarCruft / APT37. TTP: Use Mi…

C 493 99 Updated May 16, 2023

Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll

C 482 56 Updated Feb 3, 2022

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.

C 454 62 Updated Apr 22, 2025

A Linux Host-based Intrusion Detection System based on eBPF.

C 450 86 Updated Dec 20, 2023

Local privilege escalation via PetitPotam (Abusing impersonate privileges).

C 447 55 Updated Mar 30, 2023

PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.

C 434 49 Updated Jun 15, 2024

C++ self-Injecting dropper based on various EDR evasion techniques.

C 414 71 Updated Feb 11, 2024

Fast Conversion Windows Dynamic Link Library To ShellCode

C 412 135 Updated Mar 10, 2022

CVE-2023-0386在ubuntu22.04上的提权

C 408 63 Updated Jun 13, 2023

The first analysis framework for CPU microcode

C 402 26 Updated Mar 13, 2023

BOF implementation of @_EthicalChaos_'s ThreadlessInject project. A novel process injection technique with no thread creation, released at BSides Cymru 2023.

C 388 55 Updated Jan 9, 2024

Harvest passwords automatically from OpenSSH server

C 376 40 Updated May 25, 2023

CVE-2023-32233: Linux内核中的安全漏洞

C 371 79 Updated May 16, 2023

.NET assembly loader with patchless AMSI and ETW bypass

C 355 51 Updated Apr 19, 2023

nginx WebShell/内存马,更优雅的nignx backdoor

C 318 42 Updated Jan 4, 2024

COFF file (BOF) for managing Kerberos tickets.

C 317 32 Updated Jul 2, 2023

添加计划任务方法集合

C 302 48 Updated Aug 6, 2023

New lateral movement technique by abusing Windows Perception Simulation Service to achieve DLL hijacking code execution.

C 301 49 Updated Feb 23, 2022

Beacon Object File Loader

C 296 39 Updated Dec 3, 2023

CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking

C 283 37 Updated Jun 8, 2023

一款dump hash工具配合后渗透的利用

C 276 37 Updated Apr 21, 2023

EDRSandblast-GodFault

C 268 50 Updated Aug 28, 2023

Porting of BOF InlineExecute-Assembly to load .NET assembly in process but with patchless AMSI and ETW bypass using hardware breakpoint.

C 260 34 Updated Apr 17, 2023