Skip to content
View ZacharyZcR's full-sized avatar
  • 09:48 (UTC +08:00)

Block or report ZacharyZcR

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
22 stars written in C
Clear filter

A little tool to play with Windows security

C 21,118 4,008 Updated May 11, 2025

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

C 14,274 2,087 Updated Dec 19, 2025

The pattern matching swiss knife

C 9,282 1,544 Updated Nov 26, 2025

windows-kernel-exploits Windows平台提权漏洞集合

C 8,547 2,868 Updated Jun 11, 2021

FreeRTOS kernel files only, submoduled into https://github.com/FreeRTOS/FreeRTOS and various other repos.

C 3,723 1,398 Updated Nov 12, 2025

Using Zygisk to dump il2cpp data at runtime

C 2,946 8,529 Updated Aug 9, 2024

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).

C 2,281 284 Updated Oct 31, 2025

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

C 2,049 456 Updated Dec 1, 2025

Red-Team LKM

C 623 87 Updated Dec 16, 2025

Dump various types of Windows credentials without injecting in any process.

C 435 145 Updated Jan 13, 2023

Process Injection using Thread Name

C 285 37 Updated Apr 18, 2025

Cybersecurity research results. Simple C/C++ and Python implementations

C 283 65 Updated Dec 14, 2025

Linux Loadable Kernel Module (LKM) based rootkit (ring-0), capable of hiding itself, processes/implants, rmmod proof, has ability to bypass infamous rkhunter antirootkit.

C 261 59 Updated Dec 6, 2025

Waiting Thread Hijacking - injection by overwriting the return address of a waiting thread

C 257 21 Updated Aug 31, 2025

Matryoshka - stacked LKM loader

C 54 13 Updated Oct 8, 2023

Universal Linux LKM rootkit, designed to work in any kernel version and both architectures (i686 and x86_64).

C 50 15 Updated Jan 15, 2024

研究笔记/Research Report

C 27 3 Updated Apr 19, 2025

Stealthy DLL injector using thread hijacking and remote gadgets — no OpenProcess or CreateRemoteThread.

C 25 1 Updated Dec 1, 2025

Kernel module that allows hiding files in any filesystem

C 23 Updated Dec 20, 2024

Windows、Linux持久化套件/Windows, Linux persistence suite

C 18 2 Updated May 17, 2024

Windows process injection methods

C 6 23 Updated Feb 2, 2023