Skip to content
View VirtualAlllocEx's full-sized avatar
🏠
Working from home
🏠
Working from home

Sponsoring

@BC-SECURITY

Highlights

  • Pro

Block or report VirtualAlllocEx

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Evasive shellcode loader

C++ 391 63 Updated Oct 17, 2024

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by performing on-the-fly decryption of individual encry…

C++ 570 86 Updated Jun 12, 2024

Windows Local Privilege Escalation Cookbook

PowerShell 1,193 189 Updated Jan 20, 2025

Payload Generation Framework

VBA 93 12 Updated Mar 16, 2024

An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer

C++ 520 78 Updated Feb 13, 2024

A little tool to play with Windows security

C 20,879 3,980 Updated May 11, 2025

This repository contains sample programs written primarily in C and C++ for learning native code reverse engineering.

C 691 103 Updated Oct 5, 2025

This repository contains sample programs that mimick behavior found in real-world malware. The goal is to provide source code that can be compiled and used for learning purposes, without having to …

C 665 80 Updated Jul 6, 2024

DLL Unlinking from InLoadOrderModuleList, InMemoryOrderModuleList, InInitializationOrderModuleList, and LdrpHashTable

Nim 57 15 Updated Dec 15, 2023

PoC Implementation of a fully dynamic call stack spoofer

C++ 843 103 Updated Jul 20, 2024

C++ self-Injecting dropper based on various EDR evasion techniques.

C 408 71 Updated Feb 11, 2024

Utilizing hardware breakpoints to evade monitoring by Endpoint Detection and Response platforms

C++ 130 20 Updated Dec 20, 2022

Shellcode Loader Implementing Indirect Dynamic Syscall , API Hashing, Fileless Shellcode retrieving using Winsock2

C++ 294 47 Updated Jul 15, 2023

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

Rust 258 43 Updated Jun 29, 2024

OSCP 2023 Preparation Guide | Courses, Tricks, Tutorials, Exercises, Machines

1,044 229 Updated Oct 27, 2024

Remote Shellcode Injector

C++ 219 40 Updated Aug 27, 2023

Security product hook detection

C++ 318 51 Updated Mar 30, 2021

HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.

C++ 698 107 Updated Jul 19, 2023

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

PowerShell 2,637 519 Updated Jul 6, 2025

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

Python 1,518 193 Updated Jul 31, 2024

Intro to x86 Assembly Language.

Assembly 282 57 Updated Apr 29, 2020

The Havoc Framework

Go 7,888 1,127 Updated Jul 10, 2025

Powershell script to do domain auditing automation

PowerShell 395 106 Updated Apr 8, 2025

Audit tool for Active Directory. Automates a lot of checks from a pentester perspective.

PowerShell 175 40 Updated Jul 7, 2025

Cheatsheet for the commands learned in Attack and Defense Active Directory Lab

226 72 Updated Dec 4, 2022

Pentesting cheatsheet with all the commands I learned during my learning journey. Will try to to keep it up-to-date.

C++ 1,471 245 Updated Oct 9, 2025

Stealing Signatures and Making One Invalid Signature at a Time

Python 2,324 481 Updated Aug 11, 2021
Next