Skip to content
View cowbe0x004's full-sized avatar

Block or report cowbe0x004

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
190 stars written in C
Clear filter

Open source firmware for Ingenic T20 based devices such as WyzeCam V2, Xiaomi Xiaofang 1S, iSmartAlarm's Spot+ and others.

C 776 80 Updated Dec 27, 2023

CTF Cheat Sheet + Writeups / Files for some of the Cyber CTFs that I've done

C 769 60 Updated Mar 11, 2025

Tool for extracting information from newly spawned processes

C 769 112 Updated May 11, 2025

A .NET Runtime for Cobalt Strike's Beacon Object Files

C 754 109 Updated Sep 4, 2024

Linux Kernel Hacking

C 745 136 Updated Apr 10, 2024

Anything about kernel security. CTF kernel pwn, kernel exploit, kernel fuzz and kernel defense paper, kernel debugging technique, kernel CVE debug.

C 735 87 Updated Sep 5, 2025

The official home of the LibVMI project is at https://github.com/libvmi/libvmi.

C 725 255 Updated Apr 9, 2025

[Linux] Two Privilege Escalation techniques abusing sudo token

C 721 116 Updated Apr 14, 2019

The Python interface for YARA

C 715 188 Updated May 27, 2025

Various Cobalt Strike BOFs

C 705 62 Updated Oct 16, 2022

PoC exploits for software vulnerabilities

C 683 158 Updated Aug 21, 2021

Linux audit userspace repository

C 676 229 Updated Oct 30, 2025

A handy collection of my public exploits, all in one place.

C 667 119 Updated Nov 10, 2025

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vanity-a-new-approach-to-code-injection--edr-bypass…

C 661 87 Updated Dec 23, 2022

Aims to identify sleeping beacons

C 635 60 Updated Dec 9, 2024

some gadgets about windows process and ready to use :)

C 611 96 Updated Oct 7, 2023

Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team.

C 609 111 Updated Aug 5, 2022

Red-Team Linux kernel rootkit

C 597 86 Updated Oct 27, 2025

Raw binary firmware analysis software

C 562 61 Updated Jun 6, 2024

kadimus is a tool to check and exploit lfi vulnerability.

C 553 131 Updated Aug 17, 2020

Simulate the behavior of AV/EDR for malware development training.

C 547 49 Updated Feb 15, 2024

Linux Kernel Runtime Guard

C 547 85 Updated Oct 11, 2025

This repository includes code and IoCs that are the product of research done in Akamai's various security research teams.

C 517 77 Updated Jun 10, 2025

Linux Kernel Rootkit for modern kernels (6x)

C 476 67 Updated Nov 7, 2025

An in depth tutorial on how to do binary exploitation

C 452 59 Updated Jun 19, 2018

Haka runtime

C 451 62 Updated Nov 22, 2017

Module Stomping, No New Thread, HellsGate syscaller, UUID Shellcode Runner for x64 Windows 10!

C 449 87 Updated Mar 8, 2023

Proof of concept code for Datadog Security Labs referenced exploits.

C 447 62 Updated Aug 18, 2025

PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.

C 434 49 Updated Jun 15, 2024

Dump various types of Windows credentials without injecting in any process.

C 431 144 Updated Jan 13, 2023