Lists (32)
Sort Name ascending (A-Z)
Android
安卓逆向BlueTeam/Digital Forensic
应急响应、数字取证Bypass UAC/AMSI
BypassEDR/AVs
免杀,C、C++、C#、Power shell等C2/RAT
远控、C2等Cloud/Docker/K8s
云安全/容器安全等Coding
各种语言方面的知识Defender
蓝队,防守DLL/Process Hijacking
劫持,DLL劫持Domain/Internet
域相关,内网Drivers
Windows/Linux驱动开发Elevation of Privileges
Win/Linux 提权技术Hook/Unhook
Hunter
恶意软件检测/防护/识别Injection
进程注入、DLL注入、Shellcode注入等InterestingSomeThing
IOT/Wifi/Industrial
物联网/WIFI/工控等硬件安全Lateral Movement
Linux
Malware
病毒,程序开发NetWork
网络Obfuscation/Encrypt/Decrypt
混淆,加密,编码Packer/Shell
壳、加密器Persistence
权限维持Phishing
Proxy
RedTeam
ReadTeam/PenstestReverse
逆向rootkits
ShellCode/Loader
Stealer/keylogger/sniffer
窃密器/键盘记录等Windows/R3/R0
Windows开发,内核Starred repositories
A C Implementation for using a new method to invoke undetectable indirect syscalls
🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications
An experimental high-performance DNS query bruteforce tool built with AF_XDP for extremely fast and accurate bulk DNS lookups.
APT Emulation tool to exfiltrate sensitive .docx, .pptx, .xlsx, .pdf files
OCRmyPDF adds an OCR text layer to scanned PDF files, allowing them to be searched
C++ Encrypted SSL/TLS REVERSE SHELL, designed to provide secure, encrypted communication between a compromised client and an attacker, while blending seamlessly into HTTP traffic.
DDSpoof is a tool that enables DHCP DNS Dynamic Update attacks against Microsoft DHCP servers in AD environments.
Automated DLL Sideloading Tool With EDR Evasion Capabilities
TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight different programming languages.
A tool designed to increase privacy on Windows and counter malware using various techniques.
主要记录网络安全学习笔记,包含WEB安全、提权、APP渗透、内网渗透、横向移动、红队、工具学习等
ArgFuscator.net is an open-source, stand-alone web application that helps generate obfuscated command lines for common system-native executables.
WinVisor - A hypervisor-based emulator for Windows x64 user-mode executables using Windows Hypervisor Platform API
Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods
A PoC for Early Cascade process injection technique.
ZigStrike, a powerful Payload Delivery Pipeline developed in Zig, offering a variety of injection techniques and anti-sandbox features.
drizzleDumper是一款基于内存搜索的Android脱壳工具。
Divulge Stealer a highly advanced info-stealer that outperforms its predecessor, Umbral-Stealer by Blank-c. This new iteration is a complete overhaul with enhanced capabilities, targeting 25 major …
A Fully Undetectable C2 Server That Communicates Via Google SMTP to evade Antivirus Protections and Network Traffic Restrictions