FatCyclone's Stars
awesome-selfhosted/awesome-selfhosted
A list of Free Software network services and web applications which can be hosted on your own servers
BeichenDream/GodPotato
Idov31/Nidhogg
Nidhogg is an all-in-one simple to use windows kernel rootkit.
threatexpress/malleable-c2
Cobalt Strike Malleable C2 Design and Reference Guide
paranoidninja/CarbonCopy
A tool which creates a spoofed certificate of any online website and signs an Executable for AV Evasion. Works for both Windows and Linux
ZeroMemoryEx/Terminator
Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes
JLospinoso/gargoyle
A memory scanning evasion technique
chvancooten/NimPlant
A light-weight first-stage C2 implant written in Nim (and Rust).
CCob/ThreadlessInject
Threadless Process Injection using remote function hooking.
Cracked5pider/Ekko
Sleep Obfuscation
klezVirus/CheeseTools
Self-developed tools for Lateral Movement/Code Execution
zodiacon/windowskernelprogrammingbook
The Windows Kernel Programming book samples
ZeroMemoryEx/Amsi-Killer
Lifetime AMSI bypass
AlmondOffSec/PassTheCert
Proof-of-Concept tool to authenticate to an LDAP/S server with a certificate through Schannel
Idov31/Cronos
PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.
namazso/MagicSigner
Signtool for expired certificates
zblurx/dploot
DPAPI looting remotely and locally in Python
thefLink/DeepSleep
A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC
waldo-irc/YouMayPasser
You shall pass
S12cybersecurity/RDPCredentialStealer
RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++
rad9800/hwbp4mw
tothi/serviceDetector
Detect whether a service is installed (blindly) and/or running (if exposing named pipes) on a remote machine without using local admin privileges.
codewhitesec/Lastenzug
Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level
xalicex/Killers
Exploitation of process killer drivers
Semperis/GoldenGMSA
GolenGMSA tool for working with GMSA passwords
CymulateResearch/Blindside
Utilizing hardware breakpoints to evade monitoring by Endpoint Detection and Response platforms
0xthirteen/AssemblyHunter
Find .net assemblies locally
xalicex/LOLDrivers_finder
zyn3rgy/ClickonceHunter
Golang search engine scraper intended for identification of published ClickOnce deployments
tothi/malicious-service
Minimal Windows Service Template for demonstrating privilege escalation via weak service executable permissions