Skip to content
View onedays12's full-sized avatar

Block or report onedays12

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Provides Visual Studio integration for the NASM assembler.

Batchfile 182 54 Updated Mar 15, 2026
C 4,612 727 Updated May 10, 2026

A Go implementation of copyfail (CVE-2026-31431)

Assembly 349 75 Updated May 1, 2026

cc完整版,含手册,编译等

TypeScript 297 230 Updated Mar 31, 2026

Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code

Python 3,828 850 Updated Apr 29, 2026

UnderlayCopy is an @Adaptix-Framework post-exploitation BOF tool for copying locked files and registry hives using low-level NTFS volume access, bypassing file locks and access restrictions discree…

C 11 1 Updated Nov 25, 2025

This project is an experimental Go BOF/COFF loader created for learning, testing, and improving BOF execution from Go.

Go 1 Updated Apr 26, 2026

Repository hosting the bluehammer vulnerability

C 2,022 731 Updated Apr 9, 2026

test

C 104 18 Updated Apr 25, 2026

claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a s…

Python 1,292 221 Updated May 8, 2026

Go package for accessing PE/COFF files.

Go 5 3 Updated Sep 23, 2020

用zig实现精简版的donut,可将exe/dll/elf转换为shellcode

Zig 11 5 Updated Apr 24, 2026

BOF POC of the DSCourier project / invoking WinGet via COM

C++ 84 6 Updated Apr 23, 2026

DSCourier is a proof-of-concept that uses the WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries.

PowerShell 186 22 Updated Apr 16, 2026

Gopacket is a clean Go implementation of Impacket, a library intended for working with network protocols.

Go 632 52 Updated May 13, 2026

Go library to capture desktop to image

Go 1,551 213 Updated Jun 24, 2025

The Red Sun vulnerability repository

C++ 2,126 491 Updated Apr 15, 2026

BOF for Havoc that copies locked Windows files (SAM, SYSTEM, NTDS.dit) via raw MFT parsing — no VSS, no Registry APIs, no PowerShell

C 128 8 Updated Apr 6, 2026

Havoc C2 BOF port of the KslD.sys BYOVD technique. Credential extraction from lsass via physical memory — no OpenProcess, no auditable API calls.

C 108 11 Updated Apr 22, 2026

Extract Windows credentials directly from VM memory snapshots and virtual disks

Rust 1,278 143 Updated Apr 18, 2026

A cross-platform desktop All-in-One assistant for Claude Code, Codex, OpenCode, OpenClaw, Gemini CLI & Hermes Agent. Only official website: ccswitch.io

Rust 73,537 4,781 Updated May 18, 2026

The code is a pingback to the Dark Vortex blog: https://0xdarkvortex.dev/hiding-memory-allocations-from-mdatp-etwti-stack-tracing/

C 215 41 Updated Jan 29, 2023

Beacon Object File (BOF) Template

C 88 7 Updated Mar 9, 2026

FULL Augment Code, Claude Code, Cluely, CodeBuddy, Comet, Cursor, Devin AI, Junie, Kiro, Leap.new, Lovable, Manus, NotionAI, Orchids.app, Perplexity, Poke, Qoder, Replit, Same.dev, Trae, Traycer AI…

137,627 34,312 Updated May 10, 2026

这是一个检测SGN算法的Yara规则

YARA 5 Updated Mar 16, 2026

Stack Spoofing with Synthetic frames based on the work of namazso, SilentMoonWalk, and VulcanRaven

C 268 44 Updated Oct 16, 2024

Bring your own Unwind Data Framework

C++ 143 14 Updated Mar 15, 2026

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners and analysts.

C++ 1,217 194 Updated Jun 17, 2022

A Cobalt Strike RL built with Crystal Palace — module overloading, NtContinue entry transfer, call stack spoofing, sleep masking, and static signature removal.

C 205 37 Updated Mar 15, 2026
Next