Skip to content
View zhzyker's full-sized avatar
🔥
make bug
🔥
make bug

Organizations

@YanYun-Lab @0-sec @xiecat @pwnwiki-project @cisp-pte @Sec-Fork

Block or report zhzyker

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

A Rust template for writing Beacon Object Files (BOFs)

Rust 125 12 Updated Feb 11, 2026

A Cobalt Strike BOF implementation of the SilentHarvest registry dumping technique

C 117 12 Updated Apr 14, 2026

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

C 114 17 Updated Apr 15, 2026

Security testing toolkit for Claude Code: curated SecLists wordlists, injection payloads, and expert agents for authorized pentesting, CTFs, and bug bounties

PHP 174 27 Updated Mar 21, 2026

Modular User-Defined Reflective Loader (UDRL) built on Crystal Palace for controlled DLL execution and evasion research.

C 12 1 Updated Apr 14, 2026

Android APK security analysis tool. Decompiles DEX, scans for vulns, parses manifests and certs. Runs in your browser.

JavaScript 47 11 Updated Apr 4, 2026

BOF for Havoc that copies locked Windows files (SAM, SYSTEM, NTDS.dit) via raw MFT parsing — no VSS, no Registry APIs, no PowerShell

C 118 6 Updated Apr 6, 2026

Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)

Nim 94 10 Updated Apr 4, 2026

retrieve information via O365 and AzureAD with a valid cred

PowerShell 739 107 Updated Aug 14, 2022

An example UDC2 implementation for CrystalC2.

C 17 2 Updated Mar 23, 2026

适用于Node.js环境下的Suo5内存马.

JavaScript 48 6 Updated Mar 20, 2026

为 AI Agent 设计的 JS 逆向 MCP Server,内置反检测,基于 chrome-devtools-mcp 重构 | JS reverse engineering MCP server with agent-first tool design and built-in anti-detection. Rebuilt from chrome-devtools-mcp.

TypeScript 799 142 Updated Mar 24, 2026

SSRF plugin for burp Automates SSRF Detection in all of the Request

Java 621 59 Updated Jan 20, 2021

PHP-Code-Audit-Skill是一个专注于PHP代码审计的Skill

265 32 Updated Mar 25, 2026

Ryūjin Protector - Is a Intel Arch - BIN2BIN - PE Obfuscation/Protection/DRM tool

C++ 324 47 Updated Nov 20, 2025

x64DbgMCPServer made from c# with Claude, Windsurf and Cursor support

C# 441 72 Updated Apr 2, 2026

Local account pool, dashboard & Anthropic-compatible API proxy for Notion AI. Claude Code compatible. Built with Go + React. 本地 Notion AI 多账号池管理与 API 代理工具,兼容 Claude Code,提供配额监控、Web 反向代理与 Anthropic …

Go 28 13 Updated Mar 24, 2026

GO-RAT is a simple cross platform remote access tool (RAT) framework with a command-and-control server and client agent, designed for learning/testing in controlled environments.

Go 4 1 Updated Mar 24, 2026

Source code for the CrystalC2 client.

Kotlin 36 9 Updated Apr 2, 2026

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

Python 639 48 Updated Dec 3, 2024

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

Python 186 22 Updated Mar 14, 2026

KslDump — Why bring your own knife when Defender already left one in the kitchen?

Python 300 33 Updated Apr 13, 2026

🚀 Transparent proxy injector for Antigravity. Force SOCKS5/HTTP proxy without TUN mode on Windows. | 专为 Antigravity 打造的免 TUN 强制代理工具,支持 DLL 注入与进程流量劫持。

C++ 2,607 209 Updated Mar 8, 2026

COM-based DLL Surrogate Injection

C++ 166 18 Updated Dec 9, 2025

Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.

Nim 349 42 Updated Apr 16, 2026

ObfuXtreme is an advanced Python obfuscation tool for security research, reverse engineering education, and analysis of how obfuscation impacts static and signature-based detection.

Python 213 23 Updated Jan 6, 2026

Reverse engineering skills for Claude Code | 逆向工程 Claude Code Skills 插件

712 96 Updated Apr 13, 2026

ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.

HTML 1,902 298 Updated Jun 15, 2020

A comprehensive HTTP client MCP (Model Context Protocol) server for API testing, web automation and security testing. Provides full-featured HTTP tools with detailed logging capabilities. 为API 测试和 …

Python 8 2 Updated Jun 29, 2025

PwnPad is an affordable, hands-on hardware hacking platform built for practical learning. It features a range of challenges that walk users through key hardware security concepts, from PCB design t…

C++ 529 43 Updated Dec 5, 2025
Next