Skip to content
View cowbe0x004's full-sized avatar

Block or report cowbe0x004

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
190 stars written in C
Clear filter

Open Source Deep Packet Inspection Software Toolkit

C 4,207 957 Updated Nov 6, 2025

american fuzzy lop - a security-oriented fuzzer

C 4,001 666 Updated Jul 5, 2021

🐛 Access your device from anywhere via the web.

C 3,910 527 Updated Nov 9, 2025

MemProcFS

C 3,872 494 Updated Nov 8, 2025

State-of-the-art native debugging tools

C 3,514 445 Updated Oct 30, 2025

Simple (relatively) things allowing you to dig a bit deeper than usual.

C 3,415 550 Updated Oct 20, 2025

A Linux version of the ProcDump Sysinternals tool

C 3,054 325 Updated Oct 13, 2025

Rapid spam filtering system.

C 2,312 448 Updated Nov 9, 2025

Kernel Driver Utility

C 2,288 479 Updated Nov 8, 2025

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).

C 2,262 281 Updated Oct 31, 2025

LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)

C 2,178 471 Updated Oct 18, 2025

A post exploitation framework designed to operate covertly on heavily monitored environments

C 2,161 336 Updated Sep 29, 2021

PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.

C 2,111 295 Updated Aug 15, 2024

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

C 2,027 358 Updated May 28, 2025

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

C 2,026 446 Updated Nov 2, 2025

The swiss army knife of LSASS dumping

C 2,023 256 Updated Sep 17, 2024

Sysmon for Linux

C 1,994 208 Updated Jul 3, 2025

A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.

C 1,907 239 Updated Apr 7, 2024

LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, such as those powered by Android. The tool supports acquir…

C 1,891 359 Updated Nov 9, 2025

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

C 1,768 229 Updated Nov 3, 2024

Connect like there is no firewall. Securely.

C 1,759 157 Updated Sep 27, 2025

A network sniffer that logs all DNS server replies for use in a passive DNS setup

C 1,729 382 Updated May 28, 2024

SSH man-in-the-middle tool

C 1,724 211 Updated Jul 2, 2021

Linux eBPF backdoor over TCP. Spawn reverse shells, RCE, on prior privileged access. Less Honkin, More Tonkin.

C 1,642 182 Updated Oct 19, 2023

Post Exploitation Collection

C 1,568 360 Updated May 1, 2020

A tool to kill antimalware protected processes

C 1,484 249 Updated Jun 19, 2021

Windows Privilege Escalation from User to Domain Admin.

C 1,422 222 Updated Dec 18, 2022