Pinned Repositories
CobaltStrikeDetect
CobaltStrikeDetect
COMFinder
IDA plugin for COM
donut_ollvm
Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters
iisproxy
通过websocket在IIS8(Windows Server 2012)以上实现socks5代理
pyminhook
MinHook warp of Python
reality
grs内网穿透工具通过reality协议隐藏特征
wget
可能是windows最小的wget (862字节)
WinDump
后渗透信息/密码/凭证收集工具
zigdonut
用zig实现精简版的donut,可将exe/dll转换为shellcode
zigshellcode
howmp's Repositories
howmp/reality
grs内网穿透工具通过reality协议隐藏特征
howmp/WinDump
后渗透信息/密码/凭证收集工具
howmp/iisproxy
通过websocket在IIS8(Windows Server 2012)以上实现socks5代理
howmp/wget
可能是windows最小的wget (862字节)
howmp/donut_ollvm
Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters
howmp/CobaltStrikeDetect
CobaltStrikeDetect
howmp/COMFinder
IDA plugin for COM
howmp/zigshellcode
howmp/pyminhook
MinHook warp of Python
howmp/zigxorstr
zig compile time string encryption
howmp/WinINetLogger
WinINetLogger
howmp/BeaconKiller
一个通过etw技术查杀Cobalt Strike (http/https)Beacon的工具
howmp/LdrpHandleTlsData
定位ntdll.dll中LdrpHandleTlsData地址
howmp/zigdonut
用zig实现精简版的donut,可将exe/dll转换为shellcode
howmp/MFCFinder
静态获取MFC的MESSAGE_MAP表
howmp/pcre_static_cgo
static link pcre for golang,support window/linux
howmp/whatssl
识别客户端是否使用OpenSSL
howmp/AwesomeScript
AntSword Shell 脚本分享/示例
howmp/DNSLog
DNSLog 是一款监控 DNS 解析记录和 HTTP 访问记录的工具。
howmp/go-smb2
SMB2/3 client library written in Go.
howmp/go-socks5
SOCKS5 server in Golang
howmp/go-winio
Win32 IO-related utilities for Go
howmp/hexo-deployer-ali-oss
hexo deployer aliyun oss
howmp/python-mysql-replication
Pure Python Implementation of MySQL replication protocol build on top of PyMYSQL
howmp/SQLbackup
Oracle database backup as SQL (use small size only!)
howmp/xgo
Go CGO cross compiler