Skip to content
View kapiushion's full-sized avatar

Block or report kapiushion

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

289 stars written in C
Clear filter

a signal handler race condition in OpenSSH's server (sshd)

C 488 186 Updated Jul 1, 2024

Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll

C 483 56 Updated Feb 3, 2022

Cobalt Strike User-Defined Reflective Loader with AV/EDR Evasion in mind

C 478 81 Updated Jul 12, 2023

A reverse shell with terminal support, data tunneling, and advanced pivoting capabilities.

C 466 92 Updated Jul 10, 2024

BOF to steal browser cookies & credentials

C 466 40 Updated Nov 3, 2025

A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk

C 466 64 Updated Jul 6, 2024

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.

C 456 62 Updated Apr 22, 2025

A small x64 library to load dll's into memory.

C 450 76 Updated Nov 6, 2023

UDRL for CS

C 443 68 Updated Dec 3, 2023

C Just In Time, interpreter and compiler

C 426 24 Updated Apr 21, 2025

A beacon object file implementation of PoolParty Process Injection Technique.

C 421 49 Updated Dec 21, 2023

C++ self-Injecting dropper based on various EDR evasion techniques.

C 415 71 Updated Feb 11, 2024

An other No-Fix LPE, NTLMRelay2Self over HTTP (Webdav).

C 414 43 Updated Jan 27, 2024

Proof-of-Concept tool for extracting NTLMv1 hashes from sessions on modern Windows systems.

C 413 33 Updated Oct 27, 2025

For when DLLMain is the only way

C 408 66 Updated Oct 29, 2024

Encrypted shellcode Injection to avoid Kernel triggered memory scans

C 396 41 Updated Sep 12, 2023

Revenant - A 3rd party agent for Havoc that demonstrates evasion techniques in the context of a C2 framework

C 387 46 Updated Jul 30, 2024

A Windows potato to privesc

C 386 67 Updated Aug 26, 2024

A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.

C 361 46 Updated Feb 10, 2025

Embed a payload inside a PNG file

C 357 50 Updated Oct 24, 2024

.NET assembly loader with patchless AMSI and ETW bypass

C 356 51 Updated Apr 19, 2023

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

C 343 55 Updated Aug 29, 2025

A tiny Reverse Sock5 Proxy written in C :V

C 314 42 Updated Nov 28, 2022

LLVM plugin to transparently apply stack spoofing and indirect syscalls to Windows x64 native calls at compile time.

C 314 35 Updated Jan 17, 2024

WMI virus, because funny

C 296 57 Updated Jan 29, 2025

AdaptixFramework Extension Kit

C 292 87 Updated Nov 7, 2025

A BOF to automate common persistence tasks for red teamers

C 290 44 Updated Mar 7, 2023