Skip to content
View ybdt's full-sized avatar

Block or report ybdt

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Proof-of-Concept tool for extracting NTLMv1 hashes from sessions on modern Windows systems.

C 514 47 Updated Oct 27, 2025

Centralized resource for listing and organizing known injection techniques and POCs

667 72 Updated Dec 14, 2025

CPL remote trigger

Python 42 8 Updated Dec 28, 2025

Six Degrees of Domain Admin

Go 2,672 280 Updated Jan 14, 2026

A collection of various methods for adding user from windows

C 2 Updated Dec 23, 2025

Mimikatz implementation in pure Python

Python 3,227 412 Updated Jan 2, 2026

Extract SAM and SYSTEM using Volume Shadow Copy (VSS) API. With multiple exfiltration options and XOR obfuscation

C# 268 42 Updated Jan 13, 2026

Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form.

C++ 6,102 1,118 Updated Dec 15, 2025

BOF implementation of @_EthicalChaos_'s ThreadlessInject project. A novel process injection technique with no thread creation, released at BSides Cymru 2023.

C 393 56 Updated Jan 9, 2024

Threadless Process Injection using remote function hooking.

C# 801 89 Updated Sep 4, 2024

Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.

C# 4,432 756 Updated Jan 10, 2025

Shellcode and In-PowerShell solution for patching AMSI via Page Guard Exceptions

C++ 60 4 Updated Nov 15, 2025

BOF for Kerberos abuse (an implementation of some important features of the Rubeus).

C 528 64 Updated Nov 23, 2025

Trying to tame the three-headed dog.

C# 4,832 858 Updated Nov 14, 2025

🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

C 1,997 508 Updated Jul 13, 2022

免杀远控木马源码整理开源(银狐 winos 大灰狼 gh0st) Rat

C 659 307 Updated Nov 14, 2025

PC免杀远控winos4.0成品

29 9 Updated Mar 26, 2025

Mirror of the LuaJIT git repository

C 5,381 1,107 Updated Jan 9, 2026

A BOF that runs unmanaged PEs inline

C 676 84 Updated Oct 23, 2024

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

PowerShell 1,181 178 Updated Jan 28, 2025

A Visual Studio template used to create Cobalt Strike BOFs

C 322 55 Updated Nov 17, 2021

蓝队应急工具

YARA 541 53 Updated Jun 10, 2024

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

C++ 791 149 Updated Nov 1, 2025

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

Go 692 84 Updated Aug 26, 2025

Gain insights into COM/DCOM implementations that may be vulnerable using an automated approach and make it easy to visualize the data. By following this approach, a security researcher will hopeful…

PowerShell 154 13 Updated Nov 23, 2025

Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ONLY.

Go 828 87 Updated Dec 10, 2025

An IDA Plugin that help analyzing module that use COM

Python 229 29 Updated Oct 10, 2025

A secure sandbox environment for malware developers and red teamers to test payloads against detection mechanisms before deployment. Integrates with LLM agents via MCP for enhanced analysis capabil…

YARA 1,275 143 Updated Nov 12, 2025
Next