Stars
A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.
Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision
EDRUnChoker - fileless WMI defense that removes EDRChoker QoS throttling policies
A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.
⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡
Pre-indexed code knowledge graph, auto syncs on code changes, for Claude Code, Codex, Gemini, Cursor, OpenCode, AntiGravity, Kiro, CoPilot, and Hermes Agent — fewer tokens, fewer tool calls, 100% l…
腾讯云智能渗透黑客松 Official repository of Tencent Cloud Intelligent Penetration Hackathon. Showcasing top open-source projects of LLM-based autonomous penetration agents, including multi-agent collaboratio…
常见的攻击行为监测特征及方法,涵盖端点和流量,未包含PowerShell和Sysmon。预祝运营生活愉快!
Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.
📚 《从零开始构建智能体》——从零开始的智能体原理与实践教程
[ BOF-LAUNCHER ] -> an API for loading, executing and in-memory masking BOFs on Windows and Linux for use in C/Zig/Go/Rust agents/implants. [ Z-BEAC0N ] -> a custom-written stage-1 (aka pre-C2) sol…
Zaps arguments and environment from the process list
Plugin for JADX to integrate MCP server
Say goodbye to the complex, verbose, and laggy interaction mode of IDA Pro MCP
ripgrep recursively searches directories for a regex pattern while respecting your gitignore
x64DbgMCPServer made from c# with Claude, Windsurf and Cursor support
全自动化,微信小程序 wxapkg 包 源代码还原工具, 线上代码安全审计,支持 Windows, Macos, Linux
SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by…
Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. In C#, C++, Crystal, Python, Rust, Golang, Nim and Deno (Javascript)
BOF to run PE in Cobalt Strike Beacon without console creation
PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads
about how to make a anti-virus engine
Go 代码混淆工具,使用 AST (抽象语法树) 技术实现跨文件的代码混淆,同时保证混淆后的代码可编译和可执行。
Proxifier Alternative to redirect any Windows/MacOS/Linux TCP and UDP traffic to HTTP/Socks5 proxy
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.