Skip to content
View ntddk's full-sized avatar
  • Tokyo, Japan

Block or report ntddk

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a sacrificial Process as target process + (ACG+Bloc…

C 738 102 Updated Aug 7, 2025

LLM powered fuzzing via OSS-Fuzz.

Python 1,335 203 Updated Nov 17, 2025

A cross platform C2/post-exploitation framework.

Rust 699 221 Updated Oct 8, 2022

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

XSLT 8,205 1,104 Updated Dec 6, 2025

How to exploit a double free vulnerability in 2021. Use After Free for Dummies

Python 1,375 66 Updated Jan 31, 2025
1,458 226 Updated Jan 23, 2024

Greybox Synthesizer geared for deobfuscation of assembly instructions.

Python 162 20 Updated Feb 16, 2025

wtf is a distributed, code-coverage guided, customizable, cross-platform snapshot-based fuzzer designed for attacking user and / or kernel-mode targets running on Microsoft Windows and Linux user-m…

C++ 1,702 145 Updated Oct 23, 2025

x64 Windows PatchGuard bypass, register process-creation callbacks from unsigned code

C 208 35 Updated May 27, 2021

MODeflattener deobfuscates control flow flattened functions obfuscated by OLLVM using Miasm.

Python 198 29 Updated Jul 23, 2021

PoC for CVE-2021-28476 a guest-to-host "Hyper-V Remote Code Execution Vulnerability" in vmswitch.sys.

C 227 37 Updated Jun 1, 2021

Pack up to 3MB of data into a tweetable PNG polyglot file.

Python 2,575 157 Updated Aug 11, 2021

Binary Ninja plugin to identify obfuscated code and other interesting code constructs

Python 649 70 Updated Mar 14, 2025

This tool set can generate SECCOMP profiles for Docker images. It mainly relies on static analysis, making its results more reliable than currently available tools.

Python 70 16 Updated May 3, 2022

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

C 2,045 358 Updated May 28, 2025

Identify and remove opaque predicates and range dividers with miasm and radare2

Python 6 Updated Aug 18, 2020

SymCC: efficient compiler-based symbolic execution

C++ 854 147 Updated May 12, 2025

A booklet on machine learning systems design with exercises. NOT the repo for the book "Designing Machine Learning Systems", which is `dmls-book`

HTML 9,708 1,507 Updated Apr 15, 2023

Microsoft Threat Intelligence Security Tools

Python 1,926 340 Updated Dec 17, 2025

Open source pre-operation C2 server based on python and powershell

Python 762 158 Updated Jul 6, 2021

POC for cve-2019-1458

C++ 177 54 Updated Jan 17, 2022
Python 333 66 Updated Dec 8, 2022

Code and exercises for a workshop on z3 and angr

Python 233 41 Updated Dec 29, 2020

Load self-signed drivers without TestSigning or disable DSE. Transferred from https://github.com/DoubleLabyrinth/Windows10-CustomKernelSigners

C++ 774 156 Updated Jan 22, 2020

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA based scripts.

C# 1,056 179 Updated Jul 26, 2021

🍺🐙 ZetZ a zymbolic verifier and tranzpiler to bare metal C

Rust 1,599 52 Updated Jun 17, 2022

List of real-world threats against endpoint protection software

216 38 Updated Nov 13, 2025

Adversary Tactics - PowerShell Training

PowerShell 1,564 338 Updated Jan 22, 2020

Veil 3.1.X (Check version info in Veil at runtime)

Python 4,178 909 Updated Oct 9, 2023
Next