APT64's Stars
LordNoteworthy/al-khaser
Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
ldpreload/BlackLotus
BlackLotus UEFI Windows Bootkit
ExpLife0011/awesome-windows-kernel-security-development
windows kernel security development
es3n1n/no-defender
A slightly more fun way to disable windows defender + firewall. (through the WSC api)
hfiref0x/WinObjEx64
Windows Object Explorer 64-bit
khast3x/Redcloud
Automated Red Team Infrastructure deployement using Docker
NUL0x4C/AtomPePacker
A Highly capable Pe Packer
SergeyBel/AES
C++ AES implementation
memN0ps/redlotus-rs
Rusty Bootkit - Windows UEFI Bootkit in Rust (Codename: RedLotus)
namazso/MagicSigner
Signtool for expired certificates
realoriginal/bootlicker
A generic UEFI bootkit used to achieve initial usermode execution. It works with modifications.
hackerschoice/ssh-key-backdoor
varwara/CVE-2024-26229
CWE-781: Improper Address Validation in IOCTL with METHOD_NEITHER I/O Control Code
francisck/DanderSpritz_docs
The goal of this project is to examine, reverse, and document the different modules available in the Equation Group's DanderSpritz post-exploitation framework leaked by the ShadowBrokers
Cr4sh/SmmBackdoorNg
Updated version of System Management Mode backdoor for UEFI based platforms: old dog, new tricks
rainerzufalldererste/windows_x64_shellcode_template
An easily modifiable shellcode template for Windows x64 written in C
alfarom256/CVE-2022-3699
Lenovo Diagnostics Driver EoP - Arbitrary R/W
MovAX0xDEAD/NTOSKRNL_Emu
Library of missed NTOSKRNL import functions
rhotav/Crypto-Deobfuscator
A Deobfuscator for Crypto Obfuscator
ereb-thanatos/cossacks3-lan-server
A cross-platform server for the RTS Cossacks 3, intended for use in local area networks.
zerosum0x0-archive/archive
RedSiege/GPPDeception
This script generates a groups.xml file that mimics a real GPP to create a new user on domain-joined computers
ktp0li/crocum
OpenNebula-based PaaS for deployment and checking network labs
APT64/KernelAVKiller
Antivirus killer using ring-0 kernel driver. Antivirus processes will automatically close while the killer is running.
ktp0li/summus
š„first place on kibhack hackathon | telegram bot for cloud.ru management
ktp0li/brevis
simple link shortener
ktp0li/ktp0li
!kapybara!
wolfcod/NtfsPkg
DarkSuana/AstraLinux-Scripts
ktp0li/tessera
test assignment for an internship in VK