Skip to content
View guguyu1's full-sized avatar

Block or report guguyu1

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from modern Chromium-based and Gecko-based browsers …

C 691 101 Updated Feb 14, 2026

Extract credentials from lsass remotely

Python 2,196 263 Updated Mar 23, 2026

A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.

C 411 55 Updated Jan 11, 2026

Invoke-ArgFuscator is an open-source, cross-platform PowerShell module that helps generate obfuscated command-lines for common system-native executables.

PowerShell 275 48 Updated Feb 13, 2026

kernel callback removal (Bypassing EDR Detections)

C++ 214 42 Updated Nov 14, 2025

Smart keylogging capability to steal SSH Credentials including password & Private Key

C++ 152 23 Updated Mar 26, 2025

Next Generation C2 Framework, IoM-server/client

Go 439 63 Updated Apr 15, 2026

Pack/Encrypt/Obfuscate ELF + SHELL scripts

Shell 444 56 Updated Apr 11, 2026

Robust Cobalt Strike shellcode loader with multiple advanced evasion features

C++ 204 28 Updated Apr 21, 2025

🔥📜 Forbidden collection of Red Team sorcery 📜🔥

C 368 75 Updated Mar 23, 2026

Cobalt Strike BOF for evasive .NET assembly execution

C 313 36 Updated Mar 31, 2025

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

HTML 1,269 165 Updated Apr 13, 2026
C++ 82 17 Updated Apr 28, 2025

An even funnier way to disable windows defender. (through WSC api)

C++ 3,387 288 Updated Nov 23, 2025

A forensics tool to convert the data in the Windows srum (System Resource Usage Monitor) database to an xlsx spreadsheet.

Python 744 122 Updated Jun 5, 2025

Advanced In-Memory PowerShell Process Injection Framework

PowerShell 73 10 Updated Jul 16, 2025

Reflective shellcode loaderwith advanced call stack spoofing and .NET support.

C 231 45 Updated Sep 19, 2025

Lateral Movement as loggedon User via Speech Named Pipe COM & ISpeechNamedPipe + COM Hijacking

C# 145 17 Updated Jul 2, 2025

AV/EDR Lab environment setup references to help in Malware development

463 40 Updated Feb 19, 2025

一款内网快速打点的辅助性扫描工具,方便红队人员在内网横向移动前期的信息搜集、漏洞探测利用环节的工作开展。其工具特性主要为支持一键化三个档位的便捷式信息与漏洞扫描或每个功能模块单独式扫描探测功能。

Go 88 13 Updated Dec 14, 2022

哥斯拉jsp/jspx免杀webshell生成器

Java 209 19 Updated Apr 28, 2023

MDUT-Extend(扩展版本)

918 35 Updated Mar 27, 2026

针对PE文件的分离的攻防对抗工具,红队、研究者的好帮手。目前支持文件头伪装、证书区段感染。A no-kill confrontation tool for the separation of PE files, a good helper for red teams and researchers. Currently, file header spoofing and certificat…

Go 286 32 Updated Aug 20, 2024

基于frp-0.58.1魔改二开,随机化socks5账户密码及端口、钉钉上线下线通知、配置文件oss加密读取、域前置防止溯源、源码替换/编译混淆等

Go 385 62 Updated Aug 6, 2024

A tool for automatic patch shellcode into binary file to bypass AV. / 一个自动patch shellcode到二进制文件的工具

Python 569 79 Updated Apr 8, 2026

用于Webshell木马免杀、流量加密传输,多多支持star

1,044 77 Updated Jun 27, 2025

基于 OPSEC 的 CobaltStrike 后渗透自动化链

453 45 Updated Mar 11, 2024

Indirect Syscall implementation to bypass userland NTAPIs hooking.

C 84 7 Updated Aug 13, 2024

自动化反编译微信小程序,小程序安全评估工具,发现小程序安全问题,自动解密,解包,可还原工程目录,支持Hook,小程序修改

Go 5,751 1,180 Updated Sep 20, 2024

AV bypass while you sip your Chai!

C 221 36 Updated May 17, 2024
Next