Skip to content
View ZacharyZcR's full-sized avatar
  • 18:38 (UTC +08:00)

Organizations

@Termix-SSH

Block or report ZacharyZcR

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
29 results for source starred repositories written in C
Clear filter

The official NGINX Open Source repository.

C 29,266 7,751 Updated Feb 4, 2026

A little tool to play with Windows security

C 21,227 4,031 Updated May 11, 2025

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

C 14,643 2,139 Updated Feb 5, 2026

The pattern matching swiss knife

C 9,380 1,548 Updated Nov 26, 2025

windows-kernel-exploits Windows平台提权漏洞集合

C 8,577 2,875 Updated Jun 11, 2021

FreeRTOS kernel files only, submoduled into https://github.com/FreeRTOS/FreeRTOS and various other repos.

C 3,842 1,438 Updated Jan 30, 2026

Using Zygisk to dump il2cpp data at runtime

C 3,027 8,957 Updated Aug 9, 2024

🔥 ByteHook is an Android PLT hook library which supports armeabi-v7a, arm64-v8a, x86 and x86_64.

C 2,433 379 Updated Mar 3, 2025

Kernel Driver Utility

C 2,392 493 Updated Jan 11, 2026

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).

C 2,307 285 Updated Oct 31, 2025

🔥 ShadowHook is an Android inline hook library which supports thumb, arm32 and arm64.

C 2,202 364 Updated Jan 22, 2026

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

C 2,085 460 Updated Feb 4, 2026

Open-Source Shellcode & PE Packer

C 2,061 336 Updated Feb 3, 2024

Red-Team LKM

C 631 88 Updated Dec 16, 2025

Dump various types of Windows credentials without injecting in any process.

C 436 147 Updated Jan 13, 2023

Process Injection using Thread Name

C 296 41 Updated Apr 18, 2025

Cybersecurity research results. Simple C/C++ and Python implementations

C 290 71 Updated Jan 31, 2026

Linux Loadable Kernel Module (LKM) based rootkit (ring-0), capable of hiding itself, processes/implants, rmmod proof, has ability to bypass infamous rkhunter antirootkit.

C 263 59 Updated Dec 6, 2025

Waiting Thread Hijacking - injection by overwriting the return address of a waiting thread

C 262 21 Updated Aug 31, 2025

通杀检测基于白文件patch黑代码的免杀技术的后门

C 181 31 Updated Aug 3, 2024

about how to make a anti-virus engine

C 104 29 Updated May 22, 2025

Matryoshka - stacked LKM loader

C 54 13 Updated Oct 8, 2023

Universal Linux LKM rootkit, designed to work in any kernel version and both architectures (i686 and x86_64).

C 50 15 Updated Jan 15, 2024

研究笔记/Research Report

C 27 3 Updated Apr 19, 2025

Stealthy DLL injector using thread hijacking and remote gadgets — no OpenProcess or CreateRemoteThread.

C 27 1 Updated Dec 1, 2025

Kernel module that allows hiding files in any filesystem

C 23 Updated Dec 20, 2024

Windows、Linux持久化套件/Windows, Linux persistence suite

C 18 2 Updated May 17, 2024

Windows process injection methods

C 7 24 Updated Feb 2, 2023