Skip to content
View hyperware1337's full-sized avatar
:shipit:
project is about to be released to start new era (seriously)
:shipit:
project is about to be released to start new era (seriously)
  • space time

Block or report hyperware1337

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
299 stars written in C
Clear filter

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

C 1,305 210 Updated Oct 27, 2023

HVNC for Cobalt Strike

C 1,282 197 Updated Dec 7, 2023

A modern 32/64-bit position independent implant template

C 1,263 204 Updated Mar 21, 2025

LoadLibrary for offensive operations

C 1,164 208 Updated Oct 22, 2021

Collection of PoC and offensive techniques used by the BlackArrow Red Team

C 1,136 189 Updated Jul 19, 2024

Fully decrypt App-Bound Encrypted (ABE) cookies, passwords & payment methods from Chromium-based browsers (Chrome, Brave, Edge) - all in user mode, no admin rights required.

C 1,133 198 Updated Nov 7, 2025

Original C Implementation of the Hell's Gate VX Technique

C 1,121 130 Updated Jun 28, 2021

C/C++ source obfuscator for antivirus bypass

C 1,060 190 Updated Mar 10, 2022

Cobalt Strike UDRL for memory scanner evasion.

C 985 168 Updated Jun 4, 2024

Linux LD_PRELOAD rootkit (x86 and x86_64 architectures)

C 964 194 Updated Dec 11, 2020

Complete list of LPE exploits for Windows (starting from 2023)

C 837 114 Updated Nov 5, 2025

ebpfkit is a rootkit powered by eBPF

C 817 94 Updated Feb 28, 2023

助力每一位RT队员,快速生成免杀木马

C 811 105 Updated Apr 17, 2024

Azazel is a userland rootkit based off of the original LD_PRELOAD technique from Jynx rootkit. It is more robust and has additional features, and focuses heavily around anti-debugging and anti-dete…

C 804 181 Updated Mar 7, 2024

Sleep Obfuscation

C 798 110 Updated Dec 3, 2023

AV Evasion Tool For Red Team Ops

C 769 151 Updated Dec 8, 2021

A .NET Runtime for Cobalt Strike's Beacon Object Files

C 754 109 Updated Sep 4, 2024

内网域渗透小工具

C 731 132 Updated Apr 20, 2021

Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a sacrificial Process as target process + (ACG+Bloc…

C 727 99 Updated Aug 7, 2025

InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assembly execution as an alternative to Cobalt Strikes traditiona…

C 710 137 Updated Jul 22, 2023

Execute unmanaged Windows executables in CobaltStrike Beacons

C 705 105 Updated Mar 4, 2023

Various Cobalt Strike BOFs

C 704 62 Updated Oct 16, 2022

Process Ghosting - a PE injection technique, similar to Process Doppelgänging, but using a delete-pending file instead of a transacted file

C 669 121 Updated Mar 11, 2024

A BOF that runs unmanaged PEs inline

C 661 80 Updated Oct 23, 2024

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vanity-a-new-approach-to-code-injection--edr-bypass…

C 661 87 Updated Dec 23, 2022

Collection of Beacon Object Files (BOF) for Cobalt Strike

C 650 93 Updated Aug 15, 2025

A roadmap to learn C from Scratch

C 644 32 Updated Sep 21, 2024

HackRF software and captures by everyone and for everyone. Argh matey.

C 625 49 Updated Nov 13, 2024

some gadgets about windows process and ready to use :)

C 611 96 Updated Oct 7, 2023

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM experiments.

C 609 165 Updated Oct 9, 2023