Skip to content
View shadowLiar's full-sized avatar
🌴
On vacation
🌴
On vacation

Block or report shadowLiar

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
30 stars written in C
Clear filter

Display and control your Android device

C 133,024 12,429 Updated Dec 22, 2025

Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.

C 14,888 1,575 Updated Dec 20, 2025

Defeating Windows User Account Control

C 7,214 1,406 Updated Dec 14, 2025

Simple (relatively) things allowing you to dig a bit deeper than usual.

C 3,426 553 Updated Oct 20, 2025

🌴Linux、macOS、Windows Kernel privilege escalation vulnerability collection, with compilation environment, demo GIF map, vulnerability details, executable file (提权漏洞合集)

C 3,187 692 Updated Feb 15, 2023

generate CobaltStrike's cross-platform payload

C 2,523 373 Updated Nov 20, 2023

Global Proxy for Android

C 2,412 731 Updated Sep 25, 2024

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

C 2,055 456 Updated Dec 19, 2025

The swiss army knife of LSASS dumping

C 2,045 258 Updated Sep 17, 2024

A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.

C 1,922 240 Updated Apr 7, 2024

Dump cookies and credentials directly from Chrome/Edge process memory

C 1,381 131 Updated Sep 19, 2025

HVNC for Cobalt Strike

C 1,294 199 Updated Dec 7, 2023

Credentials Dumper for Linux using eBPF

C 1,156 65 Updated Sep 9, 2024

AV/EDR Evasion

C 896 168 Updated Dec 18, 2025

助力每一位RT队员,快速生成免杀木马

C 818 106 Updated Apr 17, 2024

xfrpc 是一个轻量级的 FRP 客户端,完美兼容 frps,采用 C 语言实现,专为 OpenWRT 和物联网等资源受限系统优化设计。它针对 ROM 和 RAM 空间有限的设备,提供高效的内网穿透解决方案。xfrpc 集成了xDPI(深度包检测)功能,增强了安全性,有效防止内网穿透中因恶意嗅探导致的安全威胁,确保数据传输和网络访问的可靠保护。技术交流QQ群 331230369

C 794 108 Updated Jun 2, 2025

TCP Port Redirection Utility

C 751 118 Updated Jan 31, 2023

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

C 735 106 Updated May 23, 2025

内网域渗透小工具

C 731 133 Updated Apr 20, 2021

A BOF that runs unmanaged PEs inline

C 677 83 Updated Oct 23, 2024

免杀,bypassav,免杀框架,nim,shellcode,使用nim编写的shellcode加载器

C 670 124 Updated Feb 18, 2025

免杀远控木马源码整理开源(银狐 winos 大灰狼 gh0st) Rat

C 632 296 Updated Nov 14, 2025

A socksv5 proxy tool Written by CLang. 一款纯C实现的轻量内网穿透工具,支持正向,反向socks5代理隧道的搭建,支持跨平台使用。

C 465 69 Updated Mar 2, 2025

BOF implementation of @_EthicalChaos_'s ThreadlessInject project. A novel process injection technique with no thread creation, released at BSides Cymru 2023.

C 393 56 Updated Jan 9, 2024

A Windows potato to privesc

C 390 67 Updated Aug 26, 2024

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

C 337 25 Updated Jul 20, 2024

RunPE implementation with multiple evasive techniques

C 257 34 Updated Sep 25, 2025

一个轻量级的 socks5 代理, 带简单加密传输功能, 可穿透 GFW

C 222 110 Updated Apr 13, 2016

基于Tinynuke修复得到的HVNC

C 187 58 Updated Sep 4, 2021

Self-cleaning in-memory PICO loader for Crystal Palace. Automatically erases traces and operates entirely in memory for stealthy payload execution.

C 47 3 Updated Nov 2, 2025