Skip to content
View ewilded's full-sized avatar
🌴
On vacation
🌴
On vacation

Block or report ewilded

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

Unauthenticated start EFS service on remote Windows host (make PetitPotam great again)

Python 125 10 Updated Oct 23, 2025

Gain insights into COM/DCOM implementations that may be vulnerable using an automated approach and make it easy to visualize the data. By following this approach, a security researcher will hopeful…

PowerShell 154 13 Updated Nov 23, 2025

EDR-Redir : a tool used to redirect the EDR's folder to another location.

C++ 210 36 Updated Nov 6, 2025

PowerShell tool that shows how to read and write NTLM OWF values via samlib.dll.

PowerShell 72 11 Updated Oct 22, 2025

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

PowerShell 232 24 Updated Oct 30, 2025

Driver Buddy Revolutions for Ghidra

Python 36 8 Updated Dec 18, 2025

IOCTL++ can be used to make DeviceIoControl requests with arbitrary inputs.

14 3 Updated Oct 28, 2025

Python Command-Line Ghidra MCP

Python 155 14 Updated Dec 21, 2025

PoC for popping a system shell against the LnvMSRIO.sys driver

C++ 116 12 Updated Oct 6, 2025

Decyx: AI-powered Ghidra extension for enhanced reverse engineering and binary analysis.

Python 117 4 Updated Nov 26, 2025

DriverBuddyGhidra is a collection of Python scripts for analyzing Windows drivers in Ghidra, such as finding device names and IOCTL handlers

Python 3 Updated Oct 26, 2024

Intercept Windows Named Pipes communication using Burp or similar HTTP proxy tools

Python 280 17 Updated Sep 18, 2025

Direct access to NTFS volumes

Rust 291 25 Updated Sep 9, 2025

A serie of exploits targeting eneio64.sys - Turning Physical Memory R/W into Virtual Memory R/W

C++ 105 21 Updated Oct 19, 2025

Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks

Python 402 56 Updated Jul 4, 2025

A set of plugins for Ghidra and x64Dbg synchronization. A faster, more flexible ret-sync.

C++ 96 9 Updated Nov 11, 2025

MCP Monitoring with eBPF

C 481 70 Updated Dec 7, 2025

Self-contained script for cleaning forensic traces on Linux, macOS, and Windows.

Shell 213 15 Updated Jul 25, 2025

Automatically identify and extract potential anti-debugging techniques used by malware.

Java 26 1 Updated Nov 20, 2024

Gain insights into MS-RPC implementations that may be vulnerable using an automated approach and make it easy to visualize the data. By following this approach, a security researcher will hopefully…

C# 322 40 Updated Oct 20, 2025

The fastest and more comprehensive multiprotocol credentials bruteforcer / password sprayer and enumerator. 🥷

Rust 1,776 113 Updated Sep 18, 2025

Lateral Movement via Bitlocker DCOM interfaces & COM Hijacking

C# 407 54 Updated Jun 27, 2025

AI Red Teaming playground labs to run AI Red Teaming trainings including infrastructure.

TypeScript 1,760 261 Updated Dec 22, 2025

Monkey365 provides a tool for security consultants to easily conduct not only Microsoft 365, but also Azure subscriptions and Microsoft Entra ID security configuration reviews.

PowerShell 1,214 135 Updated Sep 5, 2025

A user-mode code and its rootkit that will Kill EDR Processes permanently by leveraging the power of Process Creation Blocking Kernel Callback Routine registering and ZwTerminateProcess.

C++ 250 51 Updated Jun 10, 2025

SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai.

C# 364 58 Updated Sep 26, 2025

Python3 utility for creating zip files that smuggle additional data for later extraction

Python 262 26 Updated May 15, 2025
Shell 234 33 Updated Aug 14, 2024

A multi-threaded PDF password cracking utility equipped with commonly encountered password format builders and dictionary attacks.

Rust 1,279 131 Updated Nov 13, 2025
Next