Skip to content
View 3v4Si0N's full-sized avatar
🏠
Working from home
🏠
Working from home

Highlights

  • Pro

Block or report 3v4Si0N

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
35 stars written in C
Clear filter

Simple (relatively) things allowing you to dig a bit deeper than usual.

C 3,416 550 Updated Oct 20, 2025

Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a library from memory into a host process.

C 3,136 813 Updated Sep 3, 2022

PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.

C 2,111 295 Updated Aug 15, 2024

Open-Source Shellcode & PE Packer

C 2,021 334 Updated Feb 3, 2024

Situational Awareness commands implemented using Beacon Object Files

C 1,614 263 Updated Oct 22, 2025

A tool to kill antimalware protected processes

C 1,483 249 Updated Jun 19, 2021

CVE-2020-0796 - Windows SMBv3 LPE exploit #SMBGhost

C 1,341 342 Updated Dec 7, 2020

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

C 1,306 210 Updated Oct 27, 2023

HVNC for Cobalt Strike

C 1,279 196 Updated Dec 7, 2023

PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)

C 1,112 313 Updated May 4, 2023

C/C++ source obfuscator for antivirus bypass

C 1,060 190 Updated Mar 10, 2022

Cobalt Strike UDRL for memory scanner evasion.

C 985 168 Updated Jun 4, 2024

Complete list of LPE exploits for Windows (starting from 2023)

C 835 114 Updated Nov 5, 2025

Windows Elevation(持续更新)

C 660 167 Updated Feb 19, 2022

Collection of Beacon Object Files

C 617 115 Updated Nov 1, 2022

PIC lsass dumper using cloned handles

C 595 106 Updated Oct 18, 2022

Skrull is a malware DRM, that prevents Automatic Sample Submission by AV/EDR and Signature Scanning from Kernel. It generates launchers that can run malware on the victim using the Process Ghosting…

C 458 86 Updated Oct 25, 2021

Module Stomping, No New Thread, HellsGate syscaller, UUID Shellcode Runner for x64 Windows 10!

C 449 87 Updated Mar 8, 2023

Proof-of-Concept tool for extracting NTLMv1 hashes from sessions on modern Windows systems.

C 407 33 Updated Oct 27, 2025

A clean and blue BSPWM setup

C 362 32 Updated Jun 13, 2024

A list of all the DLLs export in C:\windows\system32\

C 219 35 Updated Dec 22, 2021

InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assembly execution as an alternative to Cobalt Strikes traditiona…

C 196 29 Updated Jul 9, 2021

A demo of the relevant blog post: https://www.arashparsa.com/hook-heaps-and-live-free/

C 192 38 Updated Sep 9, 2021

Collection of beacon object files for use with Cobalt Strike to facilitate 🐚.

C 181 26 Updated Feb 11, 2021

Simple EDR implementation to demonstrate bypass

C 181 40 Updated May 27, 2020
Next