Skip to content
View cghdev's full-sized avatar

Block or report cghdev

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Certighost POC

Python 202 42 Updated Jul 24, 2026

A Raspberry Pi-based Ethernet implant that bypasses 802.1X and allows the same IP address to be used in parallel. presented on x33fcon 2026

Python 5 1 Updated Jun 25, 2026

A Proof of Concept demonstrating CET-compliant callstack spoofing in Rust. It leverages Windows Thread Pool and Enum Callback trampolining (e.g., EnumSystemLocalesEx) to forge a pristine, hardware-…

Rust 47 7 Updated Jul 12, 2026

BingusLdr is a DLL loader built with Crystal Palace that uses a CET compatible stack spoofing technique.

C 110 10 Updated Jul 14, 2026

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and staging location for shellcode injection into remote …

C 186 22 Updated Jul 8, 2026

A stealthy and modular Windows loader designed to bypass modern EDR solutions using Module Stomping, Stack Duplication, and Advanced Sleep Obfuscation.

C 72 9 Updated Jul 26, 2026

Dump TGTs remotely and convert Windows' klist binary output to ccache.

Python 88 11 Updated Jun 30, 2026

Havoc C2 BOF port of the KslD.sys BYOVD technique. Credential extraction from lsass via physical memory — no OpenProcess, no auditable API calls.

C 144 16 Updated Apr 22, 2026

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

Python 163 14 Updated Jul 22, 2026

A shellcode loader generator with support for multiple injection techniques, built for red team engagements.

C 99 25 Updated Jul 1, 2026

Offensive knowledge, offline. One search box for every playbook.

Python 191 20 Updated Jul 1, 2026

Open Source implementation of PsPipeJack

C# 24 1 Updated May 27, 2026

Beacon Object File for LDAP Queries Through ADWS

C++ 36 3 Updated Jun 12, 2026

RoguePlanet Windows Defender Vulnerability

C++ 1,558 603 Updated Jun 9, 2026

Aegis — Unofficial Home Assistant integration for Ajax Security Systems and co-branded apps

Python 82 11 Updated Jul 26, 2026

Local SYSTEM auth trigger for relaying

C# 173 25 Updated Jul 22, 2025

Local SYSTEM auth trigger for relaying - X

C 160 16 Updated Jul 23, 2025

A credential extraction BOF for Veeam Backup and Replication and Veeam One

C 79 9 Updated Jul 1, 2026

Combining KslDump and GhostKatz to dump LSASS using no-fix KslD.sys memory read to bypass PPL. Extracts MSV1_0 NT hashes and WDigest cleartext passwords (if enabled) from LSASS using a Microsoft-si…

C++ 75 53 Updated Mar 25, 2026

.NET CLR-Stomping

C 146 21 Updated May 20, 2026

Another BYOVD process killer. works on all EDR's. fully signed.

C++ 286 53 Updated May 19, 2026

Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

C++ 421 17 Updated Jun 16, 2026

Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browsers render process sandbox

C++ 255 56 Updated May 18, 2026

This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library

318 31 Updated May 24, 2026

Home Assistant integration for Canal de Isabel II — hourly water consumption + meter reading via bookmarklet ingest.

Python 2 Updated Jul 7, 2026

x64 PE bin2bin obfuscator which doesn't add a section to the binary

C++ 291 35 Updated Jul 13, 2026

Beacon Object File to Enable Chrome DevTools Protocol (CDP)

Python 116 10 Updated Jul 1, 2026

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

C 134 10 Updated Jul 23, 2026
Next