Skip to content
View ZacharyZcR's full-sized avatar
  • Chengdu Yuzhian Technology Co., Ltd.
  • 00:18 (UTC +08:00)

Organizations

@Termix-SSH

Block or report ZacharyZcR

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
28 stars written in C
Clear filter

The official NGINX Open Source repository.

C 29,763 7,823 Updated Mar 24, 2026

A little tool to play with Windows security

C 21,357 4,046 Updated May 11, 2025

The pattern matching swiss knife

C 9,503 1,555 Updated Feb 10, 2026

windows-kernel-exploits Windows平台提权漏洞集合

C 8,623 2,865 Updated Jun 11, 2021

FreeRTOS kernel files only, submoduled into https://github.com/FreeRTOS/FreeRTOS and various other repos.

C 3,953 1,471 Updated Mar 16, 2026

Using Zygisk to dump il2cpp data at runtime

C 3,082 9,409 Updated Aug 9, 2024

Kernel Driver Utility

C 2,464 511 Updated Mar 23, 2026

🔥 ByteHook is an Android PLT hook library which supports armeabi-v7a, arm64-v8a, x86 and x86_64.

C 2,453 382 Updated Feb 28, 2026

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).

C 2,323 287 Updated Oct 31, 2025

🔥 ShadowHook is an Android inline hook library which supports thumb, arm32 and arm64.

C 2,244 373 Updated Feb 28, 2026

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

C 2,113 463 Updated Feb 19, 2026

Open-Source Shellcode & PE Packer

C 2,082 333 Updated Feb 3, 2024

Red-Team LKM

C 636 87 Updated Dec 16, 2025

Dump various types of Windows credentials without injecting in any process.

C 439 148 Updated Jan 13, 2023

Process Injection using Thread Name

C 307 40 Updated Apr 18, 2025

Cybersecurity research results. Simple C/C++ and Python implementations

C 303 72 Updated Mar 21, 2026

Linux Loadable Kernel Module (LKM) based rootkit (ring-0), capable of hiding itself, processes/implants, rmmod proof, has ability to bypass infamous rkhunter antirootkit.

C 266 59 Updated Dec 6, 2025

Waiting Thread Hijacking - injection by overwriting the return address of a waiting thread

C 264 20 Updated Aug 31, 2025

通杀检测基于白文件patch黑代码的免杀技术的后门

C 182 31 Updated Aug 3, 2024

about how to make a anti-virus engine

C 107 29 Updated May 22, 2025

Matryoshka - stacked LKM loader

C 54 14 Updated Oct 8, 2023

Universal Linux LKM rootkit, designed to work in any kernel version and both architectures (i686 and x86_64).

C 50 15 Updated Jan 15, 2024

Stealthy DLL injector using thread hijacking and remote gadgets — no OpenProcess or CreateRemoteThread.

C 27 1 Updated Dec 1, 2025

研究笔记/Research Report

C 26 3 Updated Apr 19, 2025

Kernel module that allows hiding files in any filesystem

C 24 Updated Dec 20, 2024

Windows、Linux持久化套件/Windows, Linux persistence suite

C 18 2 Updated May 17, 2024

Windows process injection methods

C 7 24 Updated Feb 2, 2023