Skip to content
View inspiringz's full-sized avatar
🎐
🎐

Block or report inspiringz

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
91 stars written in C
Clear filter

A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.

C 622 70 Updated Jan 2, 2025

Collection of UAC Bypass Techniques Weaponized as BOFs

C 619 76 Updated Feb 21, 2024

Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team.

C 608 109 Updated Aug 5, 2022

Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and ProcessDoppelgänging

C 582 85 Updated Mar 8, 2024

BOF for Kerberos abuse (an implementation of some important features of the Rubeus).

C 564 68 Updated Nov 23, 2025

Encrypted PE Loader Generator

C 548 106 Updated Apr 4, 2026

Collection of remote authentication triggers in C#

C 526 63 Updated May 15, 2024

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.

C 494 68 Updated Dec 7, 2025

The world's fastest apk (android)/java open source decompiler

C 492 49 Updated Mar 27, 2026

Cobalt Strike User-Defined Reflective Loader with AV/EDR Evasion in mind

C 486 80 Updated Jul 12, 2023

A socksv5 proxy tool Written by CLang. 一款纯C实现的轻量内网穿透工具,支持正向,反向socks5代理隧道的搭建,支持跨平台使用。

C 470 71 Updated Mar 2, 2025

A small x64 library to load dll's into memory.

C 462 80 Updated Nov 6, 2023

Module Stomping, No New Thread, HellsGate syscaller, UUID Shellcode Runner for x64 Windows 10!

C 453 86 Updated Mar 8, 2023

For when DLLMain is the only way

C 426 72 Updated Oct 29, 2024

Evasion kit for Cobalt Strike

C 419 54 Updated Apr 3, 2026

Encrypted shellcode Injection to avoid Kernel triggered memory scans

C 409 45 Updated Sep 12, 2023

BOF implementation of @_EthicalChaos_'s ThreadlessInject project. A novel process injection technique with no thread creation, released at BSides Cymru 2023.

C 395 57 Updated Jan 9, 2024

Recovering NTLM hashes from Credential Guard

C 383 24 Updated Dec 26, 2022

.NET assembly loader with patchless AMSI and ETW bypass

C 376 51 Updated Apr 19, 2023

A TCP packet diverter for Windows platform

C 341 66 Updated Jun 29, 2016

Technical notes, AD pentest methodology, list of tools, scripts and Windows commands that are useful for internal penetration tests and assumed breach exercises (red teaming).

C 308 67 Updated Apr 4, 2026

CobaltStrike BOF - Inject ETW Bypass into Remote Process via Syscalls (HellsGate|HalosGate)

C 300 56 Updated Sep 28, 2021

EarlyBird process hollowing technique (BOF) - Spawns a process in a suspended state, inject shellcode, hijack main thread with APC, and execute shellcode

C 289 62 Updated Mar 8, 2023

Reaping treasures from strings in remote processes memory

C 285 23 Updated Feb 8, 2025

Waiting Thread Hijacking - injection by overwriting the return address of a waiting thread

C 264 20 Updated Aug 31, 2025

Hide processes as a normal user in Linux.

C 261 50 Updated Jul 10, 2024

Dont Call Me Back - Dynamic kernel callback resolver. Scan kernel callbacks in your system in a matter of seconds!

C 250 35 Updated Jul 9, 2024

Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP.

C 250 27 Updated Jun 11, 2024