Skip to content
View toxy4ny's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report toxy4ny

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results
1 Updated Dec 28, 2025

Rust Based PE & Shellcode Packer

Rust 6 Updated Dec 28, 2025

A simple PoC demonstrating the vulnerability in the ThrottleStop.sys driver, showcasing arbitrary physical memory read and write capabilities, as well as virtual-to-physical address translation usi…

Rust 2 Updated Jan 15, 2026

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

Rust 18 3 Updated Jan 13, 2026

Improved version of EKKO by @5pider that Encrypts only Image Sections

C++ 126 32 Updated Feb 13, 2023

PE obfuscator with Evasion in mind

C 213 42 Updated Apr 25, 2023

Block any Process to open HANDLE to your process , only SYTEM is allowed to open handle to your process ,with that you can avoid remote memory scanners

C++ 171 26 Updated Apr 27, 2023

Set the process mitigation policy for loading only Microsoft Modules , and block any userland 3rd party modules

C++ 43 8 Updated May 6, 2023

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll , and trigger exported APIs from the export table

C++ 305 46 Updated Aug 2, 2023

This repo contains : simple shellcode Loader , Encoders (base64 - custom - UUID - IPv4 - MAC), Encryptors (AES), Fileless Loader (Winhttp, socket)

C++ 437 112 Updated Aug 2, 2023

Shellcode Loader with Indirect Dynamic syscall Implementation , shellcode in MAC format, API resolving from PEB, Syscall calll and syscall instruction address resolving at run time

C++ 320 67 Updated Aug 2, 2023

A keystroke logger targeting the Remote Desktop Protocol (RDP) related processes, It utilizes a low-level keyboard input hook, allowing it to record keystrokes in certain contexts (like in mstsc.ex…

C++ 396 66 Updated Aug 2, 2023

Encypting the Heap while sleeping by hooking and modifying Sleep with our own sleep that encrypts the heap

C++ 245 44 Updated Aug 2, 2023

Create a new thread that will suspend every thread and encrypt its stack, then going to sleep , then decrypt the stacks and resume threads

C++ 166 28 Updated Aug 2, 2023

Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime

C++ 311 52 Updated Aug 2, 2023

Github as C2 Demonstration , free API = free C2 Infrastructure

C++ 145 39 Updated Aug 2, 2023

different ntdll unhooking techniques : unhooking ntdll from disk, from KnownDlls, from suspended process, from remote server (fileless)

C++ 201 39 Updated Aug 2, 2023

Patching AmsiOpenSession by forcing an error branching

C++ 154 29 Updated Aug 2, 2023

Dropping a powershell script at %HOMEPATH%\Documents\WindowsPowershell\ , that contains the implant's path , and whenever powershell process is created, the implant will be executed too.

C++ 86 23 Updated Aug 2, 2023

Another approach of Threadless injection discovered by @_EthicalChaos_ in c that loads a module into the target process and stomps it, and reverting back memory protections and original memory state

C++ 185 35 Updated Aug 2, 2023

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

C++ 1,011 199 Updated Aug 29, 2023

Documents Exfiltration project for fun and educational purposes

C++ 145 30 Updated Oct 10, 2023

Hunt for C2 servers and phishing web sites using VirusTotal API , you can modify code to kill the malicious process

C++ 74 10 Updated May 19, 2024

A user-mode code and its rootkit that will Kill EDR Processes permanently by leveraging the power of Process Creation Blocking Kernel Callback Routine registering and ZwTerminateProcess.

C++ 252 51 Updated Jun 10, 2025
C++ 49 7 Updated Nov 26, 2025

Backdooring VSCode Projects

106 20 Updated Jun 5, 2025

The open source coding agent.

TypeScript 8 Updated Jan 11, 2026

95% token savings. 155x faster queries. 16 languages. LLMs can't read your entire codebase. TLDR extracts structure, traces dependencies, and gives them exactly what they need.

Python 571 47 Updated Jan 14, 2026
Next