Skip to content
View iNoSec2's full-sized avatar

Block or report iNoSec2

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
65 stars written in C
Clear filter

A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware. Brought to you by Winsider Seminars & Solutions, Inc. @ http://www.windows-internals…

C 13,534 1,609 Updated Feb 2, 2026

Official git repo for iodine dns tunnel

C 7,615 576 Updated Sep 4, 2025

Simple (relatively) things allowing you to dig a bit deeper than usual.

C 3,457 560 Updated Feb 3, 2026

The swiss army knife of LSASS dumping

C 2,065 262 Updated Sep 17, 2024

Fileless lateral movement tool that relies on ChangeServiceConfigA to run command

C 1,592 257 Updated Jul 10, 2023

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

C 1,397 268 Updated Nov 22, 2023

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

C 1,364 216 Updated Oct 27, 2023

Research code & papers from members of vx-underground.

C 1,351 257 Updated Dec 7, 2021

HVNC for Cobalt Strike

C 1,295 201 Updated Dec 7, 2023

A modern 32/64-bit position independent implant template

C 1,291 212 Updated Mar 21, 2025

proof-of-concept Windows Driver for injecting DLL into user-mode processes using APC

C 1,268 296 Updated May 1, 2024

Cobalt Strike UDRL for memory scanner evasion.

C 1,001 176 Updated Jun 4, 2024

Sleep Obfuscation

C 812 113 Updated Dec 3, 2023

A .NET Runtime for Cobalt Strike's Beacon Object Files

C 768 111 Updated Sep 4, 2024

Execute unmanaged Windows executables in CobaltStrike Beacons

C 711 105 Updated Mar 4, 2023

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vanity-a-new-approach-to-code-injection--edr-bypass…

C 675 89 Updated Dec 23, 2022

Collection of Beacon Object Files (BOF) for Cobalt Strike

C 669 94 Updated Aug 15, 2025

Performing Indirect Clean Syscalls

C 602 80 Updated Apr 19, 2023

EternalBlue suite remade in C/C++ which includes: MS17-010 Exploit, EternalBlue vulnerability detector, DoublePulsar detector and DoublePulsar Shellcode & DLL uploader

C 585 136 Updated May 10, 2025

Exploiting DLL Hijacking by DLL Proxying Super Easily

C 554 110 Updated Jul 9, 2023

Inject .NET assemblies into an existing process

C 508 74 Updated Jan 19, 2022

XLL Phishing Tradecraft

C 431 81 Updated May 24, 2022

Revenant - A 3rd party agent for Havoc that demonstrates evasion techniques in the context of a C2 framework

C 389 46 Updated Jul 30, 2024

Cobalt Strike BOF - Bypass AMSI in a remote process with code injection.

C 383 70 Updated Mar 8, 2023

COM Hijacking VOODOO

C 374 59 Updated Nov 27, 2025

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

C 373 57 Updated May 24, 2022

.NET assembly loader with patchless AMSI and ETW bypass

C 365 51 Updated Apr 19, 2023

A shellcode function to encrypt a running process image when sleeping.

C 340 57 Updated Sep 11, 2021

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

C 336 25 Updated Jul 20, 2024
Next