Skip to content
View antonioCoco's full-sized avatar

Block or report antonioCoco

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results
C 137 15 Updated Feb 11, 2025

The pattern matching swiss knife

C 9,306 1,545 Updated Nov 26, 2025

Authenticode-parser is a simple C library for Authenticode format parsing using OpenSSL.

C 24 9 Updated Mar 2, 2024

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made w…

PowerShell 2,044 211 Updated Dec 11, 2024

Dump the memory of any PPL with a Userland exploit chain

C++ 349 39 Updated Mar 17, 2023

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.

C++ 6,760 1,246 Updated Jul 14, 2025

Defeating Windows User Account Control

C 7,226 1,408 Updated Dec 14, 2025

Evading WinDefender ATP credential-theft

C 255 48 Updated Dec 2, 2019

Custom implementation of DbgHelp's MiniDumpWriteDump function. Uses static syscalls to replace low-level functions like NtReadVirtualMemory.

C 127 25 Updated Jan 18, 2022

A .net OLE/COM viewer and inspector to merge functionality of OleView and Test Container

C# 1,352 195 Updated Dec 9, 2024

State-of-the-art native debugging tools

C 3,567 448 Updated Dec 2, 2025

Enhanced version of the classic Spy++ tool

C++ 216 58 Updated Oct 6, 2025

Set of tools to analyze Windows sandboxes for exposed attack surface.

C# 2,253 449 Updated Nov 6, 2025

Detours with just single dependency - NTDLL

C++ 658 123 Updated Nov 25, 2025

A free Windows-compatible Operating System

C 16,701 1,995 Updated Dec 27, 2025

Abusing impersonation privileges through the "Printer Bug"

C 2,152 365 Updated Sep 10, 2020

AV/EDR evasion via direct system calls.

Assembly 1,967 273 Updated Jan 1, 2023

Hook system calls, context switches, page faults and more.

C++ 2,616 512 Updated May 9, 2023

proof-of-concept Windows Driver for injecting DLL into user-mode processes using APC

C 1,260 295 Updated May 1, 2024

Privilege Escalation Enumeration Script for Windows

PowerShell 3,609 498 Updated Dec 25, 2025

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

PowerShell 9,644 2,543 Updated Apr 25, 2024

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 73,950 16,438 Updated Dec 12, 2025

Various tips & tricks

Shell 3,714 471 Updated Dec 24, 2025

A set of .NET libraries for Windows implementing PInvoke calls to many native Windows APIs with supporting wrappers.

C# 2,019 223 Updated Dec 19, 2025

A VBA implementation of the RunPE technique or how to bypass application whitelisting.

VBA 815 179 Updated Dec 17, 2019

The ultimate WinRM shell for hacking/pentesting

Ruby 5,177 669 Updated Dec 15, 2025

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters

C 4,363 725 Updated Jul 8, 2025
Next