Skip to content
View mstxq17's full-sized avatar
🤒
Hello World!
🤒
Hello World!

Block or report mstxq17

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

39 stars written in C++
Clear filter

🎤⌨️ Acoustic keyboard eavesdropping

C++ 8,992 602 Updated Jan 15, 2023

Wechat Chat History Exporter 微信聊天记录导出备份程序

C++ 7,750 850 Updated Feb 26, 2025

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.

C++ 6,887 1,259 Updated Mar 1, 2026

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

C++ 3,582 468 Updated Oct 31, 2025

KDMapper is a simple tool that exploits iqvw64e.sys Intel driver to manually map non-signed drivers in memory

C++ 2,808 621 Updated Mar 21, 2026

shellcodeloader

C++ 1,747 386 Updated Dec 11, 2020

Alternative Shellcode Execution Via Callbacks

C++ 1,700 331 Updated Nov 11, 2022

A lightweight Universal Windows proxy app based on https://github.com/eycorsican/leaf

C++ 1,331 126 Updated Mar 5, 2025

Remove AV/EDR Kernel ObRegisterCallbacks、CmRegisterCallback、MiniFilter Callback、PsSetCreateProcessNotifyRoutine Callback、PsSetCreateThreadNotifyRoutine Callback、PsSetLoadImageNotifyRoutine Callback...

C++ 1,298 223 Updated Jun 21, 2024

Hook system calls on Windows by using Kaspersky's hypervisor

C++ 1,285 285 Updated Feb 14, 2026

Socks5/4/4a Proxy support for Remote Desktop Protocol / Terminal Services / Citrix / XenApp / XenDesktop

C++ 1,246 181 Updated Nov 2, 2022

Obfuscate specific windows apis with different apis

C++ 1,023 178 Updated Feb 21, 2021

Stop Windows Defender programmatically

C++ 992 151 Updated Nov 4, 2022

hijack dll Source Code Generator. support x86/x64

C++ 878 249 Updated Jan 25, 2021

CSLoader is a general purpose obfuscation and anti-virus tool based on a reimplementation of the llvm project obfuscator(https://github.com/obfuscator-llvm/obfuscator).

C++ 840 140 Updated Apr 2, 2025

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

C++ 814 91 Updated Mar 16, 2024

检测绝大部分所谓的内存免杀马

C++ 734 137 Updated Sep 15, 2022

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers, Unlinking .NET related modules, bypassing ETW+AMSI, avo…

C++ 595 113 Updated Jul 26, 2021

dump lsass进程工具

C++ 562 79 Updated Jul 20, 2023

A tool that detects the privilege escalation vulnerabilities caused by misconfigurations and missing updates in the Windows operating systems.

C++ 490 68 Updated Jul 23, 2020

A software for sharing in LAN

C++ 469 136 Updated Feb 2, 2026

Redirecting (specific) TCP, UDP and ICMP traffic to another destination.

C++ 428 85 Updated Mar 5, 2021

Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)

C++ 426 76 Updated Apr 22, 2021

使用windows api添加用户,可用于net无法使用时.分为nim版,c++版本,RDI版,BOF版。

C++ 421 92 Updated Sep 29, 2021

CVE-2021-1732 Exploit

C++ 421 128 Updated Mar 5, 2021

POCs for Shellcode Injection via Callbacks

C++ 412 74 Updated Feb 23, 2021

Pass in a list of URLs with query strings, get back a unique list of URLs and query string combinations

C++ 395 65 Updated Jun 17, 2020

Killing your preferred antimalware by abusing native symbolic links and NT paths.

C++ 359 81 Updated Jan 29, 2022

A PoC implementation for dynamically masking call stacks with timers.

C++ 309 38 Updated Feb 13, 2023

40行代码检测到大部分CobaltStrike的shellcode

C++ 294 53 Updated Jul 25, 2021
Next