Skip to content
View qw3rtty's full-sized avatar
⌨️
Learning and Hacking
⌨️
Learning and Hacking

Block or report qw3rtty

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

Load a dynamic library from memory by modifying the native Windows loader

C++ 291 50 Updated Jun 18, 2025

Tools for interacting with authentication packages using their individual message protocols

C++ 428 35 Updated Apr 1, 2026

InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution

Python 115 5 Updated Apr 4, 2026

PolyEngine is an evasive PE packer designed for CTF challenges and low-level Windows security education. It focuses on bypassing EDR and AV heuristics through a layered stack of in-memory execution…

C 11 Updated Mar 20, 2026

Public Repo for Atomic Test Harness

PowerShell 285 49 Updated Apr 8, 2025

Invoke-AtomicRedTeam is a PowerShell module to execute tests as defined in the [atomics folder](https://github.com/redcanaryco/atomic-red-team/tree/master/atomics) of Red Canary's Atomic Red Team p…

PowerShell 1,026 242 Updated Sep 8, 2025

Small and highly portable detection tests based on MITRE's ATT&CK.

C 11,766 3,089 Updated Mar 30, 2026

A Crystal Palace shared library to resolve & perform syscalls

C 59 6 Updated Oct 29, 2025

Easy peasy file uploads

HTML 33 6 Updated Aug 29, 2025

Dump protected process memory by using BYOVD to tamper with handle objects in the kernel.

C 39 3 Updated Aug 5, 2025

Some notes and examples for cobalt strike's functionality

1,129 140 Updated Feb 8, 2022

AdaptixC2 Templates

Go Template 26 5 Updated Apr 1, 2026

Monitor the Windows Event Log with grep-like features or filtering for specific Event IDs

Python 89 4 Updated Mar 26, 2026

Adaptix C2 agent using Crystal Palace PIC linker and PICO module system

C 71 7 Updated Mar 7, 2026

Language extension for Crystal Palace Specification files

15 1 Updated Jan 14, 2026

PICO-Implant is a Proof of Concept C2 implant built using Position-independent Code Objects (PICO) for modular functionality. This project demonstrates that It's possible to build a multi-stage and…

C 48 4 Updated Nov 9, 2025

A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike

C 195 27 Updated Oct 29, 2025

Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a library from memory into a host process.

C 3,257 820 Updated Sep 3, 2022

A secure sandbox environment for malware developers and red teamers to test payloads against detection mechanisms before deployment. Integrates with LLM agents via MCP for enhanced analysis capabil…

YARA 1,337 150 Updated Nov 12, 2025

A cross-platform tool to parse and describe the contents of a raw ntSecurityDescriptor structure

Go 48 2 Updated Oct 4, 2025

A cross-platform tool to find and decrypt Group Policy Preferences passwords from the SYSVOL share using low-privileged domain accounts

Go 171 23 Updated Jun 29, 2025

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Go 495 72 Updated Apr 1, 2021

D/Invoke standalone shellcode runners

C# 40 9 Updated Nov 23, 2023

Active Directory Vulnerability Scanner

Python 377 42 Updated Mar 3, 2026

Find jmp gadgets for call stack spoofing.

C# 79 9 Updated Oct 1, 2025

EDR-Enum-BOF AdaptixC2

C 29 3 Updated Mar 5, 2026

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without touching LSASS process memory.

C 289 36 Updated Feb 21, 2026
C 10 3 Updated Aug 7, 2025

Dll Shellcode Loader POC

C 8 2 Updated Mar 28, 2025

A Bloodhound alternative. BloodBash will ingest the same files bloodhound does but no server is required to use this tool. It's great for quick AD enumeration.

Python 181 19 Updated Mar 2, 2026
Next