Skip to content
View oXis's full-sized avatar
🦄
Fuck this shit, I'm a unicorn
🦄
Fuck this shit, I'm a unicorn

Block or report oXis

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
20 stars written in C
Clear filter

A Compiler Writing Journey

C 13,178 1,183 Updated Sep 24, 2025

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters

C 4,527 737 Updated Jul 8, 2025

Fast and lightweight x86/x86-64 disassembler and code generation library

C 4,162 483 Updated Dec 8, 2025

A hacker's userspace TCP/IP stack

C 3,089 414 Updated Dec 13, 2022

A post exploitation framework designed to operate covertly on heavily monitored environments

C 2,170 333 Updated Sep 29, 2021

A tiny neural network library

C 2,139 188 Updated Jan 17, 2021

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

C 2,122 458 Updated Apr 4, 2026

A modern 32/64-bit position independent implant template

C 1,314 213 Updated Mar 21, 2025

LoadLibrary for offensive operations

C 1,178 209 Updated Oct 22, 2021

BitTorrent DHT library

C 709 168 Updated Mar 18, 2023

PIC lsass dumper using cloned handles

C 594 109 Updated Oct 18, 2022

This repository includes code and IoCs that are the product of research done in Akamai's various security research teams.

C 528 75 Updated Mar 25, 2026

Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks by spawning sacrificial process with Arbitrary Code Guard (AC…

C 469 71 Updated Mar 8, 2023

Skrull is a malware DRM, that prevents Automatic Sample Submission by AV/EDR and Signature Scanning from Kernel. It generates launchers that can run malware on the victim using the Process Ghosting…

C 459 84 Updated Oct 25, 2021

Module Stomping, No New Thread, HellsGate syscaller, UUID Shellcode Runner for x64 Windows 10!

C 453 86 Updated Mar 8, 2023

A shellcode function to encrypt a running process image when sleeping.

C 338 57 Updated Sep 11, 2021

NINA: No Injection, No Allocation x64 Process Injection Technique

C 227 49 Updated Jun 9, 2020

Load and execute COFF files and Cobalt Strike BOFs in-memory

C 225 44 Updated Sep 13, 2022

BitTorrent DHT bootstrap node

C 72 25 Updated Dec 27, 2020