Skip to content
View koushui's full-sized avatar

Block or report koushui

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
57 stars written in C
Clear filter

TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.

C 26,072 3,247 Updated Oct 5, 2026

A little tool to play with Windows security

C 21,899 4,179 Updated Apr 17, 2026

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters

C 4,719 758 Updated Jul 8, 2025

A tool to dump the login password from the current linux user

C 4,175 652 Updated Sep 5, 2025

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

C 2,200 464 Updated Jul 28, 2026

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

C 1,912 244 Updated Nov 3, 2024

nginx WebShell/内存马,更优雅的nignx backdoor

C 321 42 Updated Jan 4, 2024

Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP.

C 249 25 Updated Jun 11, 2024

Generic PE loader for fast prototyping evasion techniques

C 246 47 Updated Jul 2, 2024

Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.

C 226 38 Updated Aug 10, 2019

ApexLdr is a DLL Payload Loader written in C

C 116 23 Updated Jul 17, 2024

Socket over DNS tunnel

C 95 30 Updated Oct 3, 2019

dns tunnel C2

C 87 24 Updated Jan 18, 2022

How to hide a hook -- A hypervisor for rootkits. Phrack 69

C 4 3 Updated Sep 22, 2020

A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.

C 2 Updated Mar 8, 2023

Layer 4 Single Packet Authentication Linux kernel module utilizing Netfilter hooks and kernel supported Berkeley Packet Filters (BPF)

C 1 Updated Nov 22, 2018

Some ways to inject a DLL into a alive process

C 1 Updated Apr 26, 2018

peinjector - MITM PE file infector

C 1 Updated May 11, 2016

Linux kernel rootkit

C 1 Updated Sep 29, 2025

LoadLibrary for Children's Paradise

C 1 Updated Mar 9, 2023

A C library for creating and using TCP/IP packets with raw network sockets

C 1 Updated Dec 20, 2024

An Attempt to Bypass Memory Scanners By Misusing the ntdll.dll "RT" Section.

C 1 Updated Jan 3, 2016

Windows driver with usermode interface which can hide objects of file-system and registry, protect processes and etc

C 1 Updated Jun 9, 2020

PoC of the communication channel implemented over DNS protocol

C 1 Updated Apr 6, 2022

Implant drop-in for EDR testing

C 1 Updated Nov 15, 2023

Post-exploitation and evasion research toolkit for Linux.

C 1 Updated Jul 22, 2026

Linux下应用层注入/hook技术实现端口复用

C 1 Updated Oct 5, 2026

SSH man-in-the-middle tool

C 1 Updated Jul 2, 2021

Code Injector Using Code Caves

C 1 Updated Jul 12, 2015
Next