Skip to content
View hyperware1337's full-sized avatar
:shipit:
project is about to be released to start new era (seriously)
:shipit:
project is about to be released to start new era (seriously)
  • space time

Block or report hyperware1337

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
283 stars written in C++
Clear filter

:electron: Build cross-platform desktop apps with JavaScript, HTML, and CSS

C++ 118,999 16,622 Updated Nov 7, 2025

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.

C++ 6,680 1,239 Updated Jul 14, 2025

An even funnier way to disable windows defender. (through WSC api)

C++ 2,954 262 Updated Oct 17, 2025

KDMapper is a simple tool that exploits iqvw64e.sys Intel driver to manually map non-signed drivers in memory

C++ 2,585 593 Updated Oct 24, 2025

A JIT assembler for x86/x64 architectures supporting FPU, MMX, SSE (1-4), AVX (1-2, 512), APX, and AVX10.2

C++ 2,194 294 Updated Sep 2, 2025

Disable PatchGuard and Driver Signature Enforcement at boot time

C++ 2,162 377 Updated Aug 3, 2025

Nidhogg is an all-in-one simple to use windows kernel rootkit.

C++ 2,131 302 Updated Oct 30, 2025

x64 binary obfuscator

C++ 1,911 272 Updated Jul 14, 2023

Modern graphing calculator operating system.

C++ 1,848 482 Updated Aug 6, 2024

Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive toolkits.

C++ 1,672 286 Updated Sep 25, 2025

Alternative Shellcode Execution Via Callbacks

C++ 1,650 321 Updated Nov 11, 2022

Examples for using ONNX Runtime for machine learning inferencing.

C++ 1,528 395 Updated Oct 31, 2025

Extracting Clear Text Passwords from mstsc.exe using API Hooking.

C++ 1,385 361 Updated Jul 20, 2024

EDR Lab for Experimentation Purposes

C++ 1,377 149 Updated Oct 26, 2025

Process Hollowing (Malware Technique)

C++ 1,364 229 Updated Oct 1, 2025

Hide your Powershell script in plain sight. Bypass all Powershell security features

C++ 1,257 171 Updated Aug 19, 2019

Remove AV/EDR Kernel ObRegisterCallbacks、CmRegisterCallback、MiniFilter Callback、PsSetCreateProcessNotifyRoutine Callback、PsSetCreateThreadNotifyRoutine Callback、PsSetLoadImageNotifyRoutine Callback...

C++ 1,246 216 Updated Jun 21, 2024

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

C++ 1,204 163 Updated Dec 11, 2023

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners and analysts.

C++ 1,170 190 Updated Jun 17, 2022

Shellcode Compiler

C++ 1,135 280 Updated Sep 1, 2024

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

C++ 1,062 161 Updated Jun 17, 2022

Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes

C++ 1,029 169 Updated Jun 20, 2023

Obfuscate specific windows apis with different apis

C++ 1,013 178 Updated Feb 21, 2021

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

C++ 995 200 Updated Aug 29, 2023

Now You See Me, Now You Don't

C++ 990 152 Updated Oct 26, 2025

A library for doing homomorphic encryption operations on tensors

C++ 975 168 Updated Feb 28, 2025

Tool to bypass LSA Protection (aka Protected Process Light)

C++ 973 145 Updated Dec 4, 2022

New version of RottenPotato as a C++ DLL and standalone C++ binary - no need for meterpreter or other tools.

C++ 963 187 Updated Dec 29, 2017

Run a Exe File (PE Module) in memory (like an Application Loader)

C++ 930 174 Updated Mar 28, 2021

Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes, protect and elevate them with token manipulation.

C++ 923 191 Updated Mar 29, 2022
Next