New activity new repos · releases
Other repos 3 · one account each
New faces newly followed accounts
- mimikatz A little tool to play with Windows security ★ 21818
- kekeo A little toolbox to play with Microsoft Kerberos in C ★ 1521
- wanakiwi Automated wanadecrypt with key recovery if lucky ★ 801
- wanadecrypt A decryptor for Wanacry (you need the private key!) ★ 183
- knrf24 Minimalist C project for Rasperry Pi Pico to drive up to 4 NRF24L01(+) modules ★ 79
- UACME Defeating Windows User Account Control ★ 7779
- KDU Kernel Driver Utility ★ 2712
- WinObjEx64 Windows Object Explorer 64-bit ★ 1974
- SyscallTables Windows NT Syscall tables ★ 1468
- TDL Driver loader for bypassing Windows x64 Driver Signature Enforcement ★ 1225
Windows Internals expert, author, and trainer. Teaching system programming & debugging at TrainSec. Check out my books & courses!
- WindowsInternals Windows Internals Book 7th edition Tools ★ 2782
- TotalRegistry Total Registry - enhanced Registry editor/viewer ★ 1639
- AllTools All reasonably stable tools ★ 1441
- SystemExplorer Windows System Explorer ★ 887
- windowskernelprogrammingbook The Windows Kernel Programming book samples ★ 686
🔴 Red Team operator. 👾 Windows malware afficionado. 🛡️ Securing the world by stealing cyber criminals' operation theater
- Penetration-Testing-Tools A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security audits purposes. ★ 3005
- ThreadStackSpoofer Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners and analysts. ★ 1245
- PackMyPayload A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats. Supports: ZIP, 7zip, PDF, ISO, IMG, CAB, VHD, VHDX ★ 1211
- ShellcodeFluctuation An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents ★ 1130
- cobalt-arsenal My collection of battle-tested Aggressor Scripts for Cobalt Strike 4.0+ ★ 1107
CTIO at CrowdStrike President of Winsider Seminars & Solutions, Inc. Follow me at @aionescu on Twitter and http://www.windows-internals.com
- SimpleVisor SimpleVisor is a simple, portable, Intel VT-x hypervisor with two specific goals: using the least amount of assembly code (10 lines), and having the smallest amount of VMX-related code to support dyna ★ 1998
- lxss Fun with the Windows Subsystem for Linux (WSL/LXSS) ★ 894
- VisualUefi A project for allowing EDK-II Development with Visual Studio ★ 610
- SpecuCheck SpecuCheck is a Windows utility for checking the state of the software mitigations and hardware against CVE-2017-5754 (Meltdown), CVE-2017-5715 (Spectre v2), CVE-2018-3260 (Foreshadow), and CVE-2018- ★ 584
- winipt The Windows Library for Intel Process Trace (WinIPT) is a project that leverages the new Intel Processor Trace functionality exposed by Windows 10 Redstone 5 (1809), through a set of libraries and a c ★ 411
Rust-focused low-level security research across Windows user-mode, kernel, UEFI, and hypervisor, with interests in reverse engineering and code obfuscation.
- redlotus-rs Rusty Bootkit - Windows UEFI Bootkit in Rust (Codename: RedLotus) ★ 583
- eagle-rs Rusty Rootkit - Windows Kernel Rookit in Rust (Codename: Eagle) ★ 581
- illusion-rs Rusty Hypervisor - Windows UEFI Blue Pill Type-1 Hypervisor in Rust (Codename: Illusion) ★ 413
- venom-rs Rusty Injection - Shellcode Reflective DLL Injection (sRDI) in Rust (Codename: Venom) ★ 370
- matrix-rs Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix) ★ 359
Lead Red Teamer & Malware Dev, Reverse engineering for fun and analyzing Winternals
- OffensiveRust Rust Weaponization for Red Team Engagements. ★ 3025
- TartarusGate TartarusGate, Bypassing EDRs ★ 673
- NamelessC2 Nameless C2 - A C2 with all its components written in Rust ★ 284
- RedLizard RedLizard Rust TCP Reverse Shell Server/Client ★ 137
- LdrLoadDll-Unhooking LdrLoadDll Unhooking ★ 130
Senior Security Consultant | кибервойна advocatus diaboli
- HellsGate Original C Implementation of the Hell's Gate VX Technique ★ 1221
- wspe Windows System Programming Experiments ★ 223
- SharpHellsGate C# Implementation of the Hell's Gate VX Technique ★ 215
- vx Virus Exchange (VX) - Collection of malware or assembly code used for "offensive" purposed. ★ 201
- exploit Collection of different exploits ★ 184
Associate Principal at Options Clearing Corporation
- pintool-example A sample cmake based project targeting Windows for Visual Studio to experiment with Intel PIN for fuzzing/instrumentation ★ 1
Infosec Noob
- laZzzy laZzzy is a shellcode loader, developed using different open-source libraries, that demonstrates different execution techniques. ★ 505
- LazyRecon An automated approach to performing recon for bug bounty hunting and penetration testing. ★ 452
- Beaconator A beacon generator using Cobalt Strike and a variety of tools. ★ 446
- KernelCallbackTable-Injection Code used in this post https://captmeelo.com/redteam/maldev/2022/04/21/kernelcallbacktable-injection.html ★ 161
- MassMap Combined port scanning w/ Masscan's speed & Nmap's scanning features. ★ 156