Skip to content
View S1hatter's full-sized avatar

Block or report S1hatter

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
102 results for source starred repositories
Clear filter

using wnbios64.sys for arbitrary r/w

C++ 13 2 Updated May 7, 2024

Living Off The Land Drivers

YARA 1,079 126 Updated Jan 13, 2025

AIDA64DRIVER Elevation of Privilege Vulnerability

C++ 11 2 Updated Oct 25, 2024

RDPWrap.ini for RDP Wrapper Library by Stas'M

2,769 773 Updated Jan 17, 2025

Super RDPWrap

C++ 2,351 326 Updated Feb 28, 2023

RDP Wrapper Library

Pascal 14,978 3,872 Updated Jun 18, 2024

An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer

C++ 475 76 Updated Feb 13, 2024

Shim database persistence (Fin7 TTP)

C 36 10 Updated Feb 25, 2020

Vulnerable driver research tool, result and exploit PoCs

Python 183 27 Updated Nov 1, 2023

An Unsigned Driver Mapper for Windows 10 22H2 -> Windows 11 23H2 that uses PdFwKrnl to exploit the Read/Write IOCTL Calls to disable DSE & PG to map the unsigned driver.

C++ 115 27 Updated Aug 29, 2024

Remove AV/EDR Kernel ObRegisterCallbacks、CmRegisterCallback、MiniFilter Callback、PsSetCreateProcessNotifyRoutine Callback、PsSetCreateThreadNotifyRoutine Callback、PsSetLoadImageNotifyRoutine Callback...

C++ 984 178 Updated Jun 21, 2024

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

Go 11,787 1,616 Updated Jan 20, 2025

Process injection alternative

C++ 314 43 Updated Sep 6, 2024

C++解析websocket协议

C++ 178 124 Updated Jun 3, 2018

canonical libwebsockets.org networking library

C 4,850 1,507 Updated Jan 20, 2025

GBFR Logs lets you track damage statistics with a nice overlay DPS meter for Granblue Fantasy: Relink.

Rust 222 25 Updated Jul 15, 2024

C++ websocket client/server library

C++ 7,185 1,997 Updated Aug 21, 2024

A BOF to determine Windows Defender exclusions.

C++ 243 37 Updated Jun 25, 2023

The version of the original Mimikatz working with Windows 11, no additional edits except the compatibility ones

C 42 7 Updated Oct 20, 2023

基于gh0st的远程控制器:实现了终端管理、进程管理、窗口管理、远程桌面、文件管理、语音管理、视频管理、服务管理、注册表管理等功能,优化全部代码及整理排版,修复内存泄漏缺陷,程序运行稳定。项目代码仅限于学习和交流用途。

C++ 957 339 Updated Jan 15, 2025

Stop Windows Defender programmatically

C++ 961 151 Updated Nov 4, 2022

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

C 1,560 196 Updated Nov 3, 2024

Converts PE into a shellcode

C++ 2,435 442 Updated Aug 15, 2023

sSocks fork for windows support; original: https://sourceforge.net/projects/ssocks/

C 42 37 Updated May 10, 2021

sSocks fork for windows support; original: https://sourceforge.net/projects/ssocks/

C 159 68 Updated Jul 8, 2020

reverse proxy server

C 20 12 Updated Jul 7, 2016

The code is a pingback to the Dark Vortex blog: https://0xdarkvortex.dev/hiding-memory-allocations-from-mdatp-etwti-stack-tracing/

C 172 35 Updated Jan 29, 2023

The code is a pingback to the Dark Vortex blog:

C 169 32 Updated Jan 26, 2023

Server/Client SOCKS5 (RFC 1928) in Reverse mode on Windows

C++ 35 15 Updated Feb 18, 2019

Process Ghosting Tool

C++ 166 24 Updated Jun 22, 2021
Next