Skip to content
View leonjza's full-sized avatar
[hip, hip]
[hip, hip]

Highlights

  • Pro

Organizations

@sensepost @eveseat @bsides-vendomatic

Block or report leonjza

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
73 stars written in C
Clear filter

SSH man-in-the-middle tool

C 1,732 212 Updated Jul 2, 2021

Some helpful preload libraries for pwning stuff.

C 1,647 177 Updated May 22, 2025

Macro-header for compile-time C obfuscation (tcc, win x86/x64)

C 1,573 130 Updated Feb 7, 2026

lwIP mirror from http://git.savannah.gnu.org/cgit/lwip.git

C 1,527 549 Updated Aug 3, 2025

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

C 1,397 269 Updated Nov 22, 2023

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens from Chrome, Edge, Brave & Avast - fileless, user-…

C 1,383 234 Updated Feb 5, 2026

A minimal status bar for macOS. Ideal for use with tiling window managers like yabai

C 1,340 49 Updated Feb 16, 2023

Native API header files for the System Informer project.

C 1,337 209 Updated May 25, 2025

A modern 32/64-bit position independent implant template

C 1,294 211 Updated Mar 21, 2025

Exercises to learn how to fuzz with American Fuzzy Lop

C 1,275 198 Updated Oct 12, 2022

Cobalt Strike UDRL for memory scanner evasion.

C 1,001 177 Updated Jun 4, 2024

Demonstrates the "heartbleed" problem using full OpenSSL stack

C 709 148 Updated Nov 6, 2016

Active Directory Control Paths auditing and graphing tools

C 678 101 Updated Dec 17, 2020

Phantom Tap (PhanTap) - an ‘invisible’ network tap aimed at red teams

C 620 82 Updated Oct 6, 2025

A port-knocking daemon

C 611 119 Updated Apr 4, 2024

A minimal TCP/IP stack

C 536 17 Updated Mar 28, 2024

Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll

C 498 57 Updated Feb 3, 2022

Skrull is a malware DRM, that prevents Automatic Sample Submission by AV/EDR and Signature Scanning from Kernel. It generates launchers that can run malware on the victim using the Process Ghosting…

C 458 84 Updated Oct 25, 2021

Module Stomping, No New Thread, HellsGate syscaller, UUID Shellcode Runner for x64 Windows 10!

C 454 87 Updated Mar 8, 2023

Evasion kit for Cobalt Strike

C 378 46 Updated Jan 17, 2026

New lateral movement technique by abusing Windows Perception Simulation Service to achieve DLL hijacking code execution.

C 301 49 Updated Feb 23, 2022

Gain observability into any Linux command or application with no code modification

C 288 36 Updated Mar 20, 2024

How to record and replay touchscreen events on an Android device.

C 255 57 Updated Jun 8, 2023

BOF that finds all the Nt* system call stubs within NTDLL and overwrites with clean syscall stubs (user land hook evasion)

C 195 19 Updated Feb 6, 2025

Pentest tool for antivirus evasion and running arbitrary payload on target Wintel host

C 175 53 Updated May 6, 2016

A Collection of In-Memory Shellcode Execution Techniques for Windows

C 152 38 Updated Jul 26, 2019