Skip to content
View mthcht's full-sized avatar
🏠
Working from home
🏠
Working from home

Sponsors

@kick707

Highlights

  • Pro

Organizations

@s1community @lolc2 @BADGUIDS

Block or report mthcht

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
26 stars written in C
Clear filter

Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.

C 13,862 1,466 Updated Jan 18, 2025

The pattern matching swiss knife

C 8,502 1,465 Updated Jan 30, 2025

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.

C 3,495 425 Updated Jan 28, 2025

MemProcFS

C 3,329 415 Updated Jan 25, 2025

Simple (relatively) things allowing you to dig a bit deeper than usual.

C 3,283 538 Updated Jan 21, 2025

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).

C 2,097 265 Updated Jan 24, 2025

Sysmon for Linux

C 1,801 191 Updated Jan 29, 2025

Credentials Dumper for Linux using eBPF

C 1,129 62 Updated Sep 9, 2024

ebpfkit is a rootkit powered by eBPF

C 775 92 Updated Feb 28, 2023

The multi-platform memory acquisition tool.

C 726 106 Updated Nov 30, 2024

SSH Session Monitoring Daemon

C 488 24 Updated May 12, 2023

Deep Linux runtime visibility meets Wireshark

C 257 11 Updated Jan 16, 2025

The Linux port of the Sysinternals Sysmon tool.

C 254 34 Updated Jan 28, 2025

Library and tools to access the Windows New Technology File System (NTFS)

C 199 54 Updated Jul 7, 2024

Monitors for DCSYNC and DCSHADOW attacks and create custom Windows Events for these events.

C 138 33 Updated Mar 7, 2018

ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits

C 125 17 Updated Feb 28, 2023

Tool designed to exfiltrate OneDrive Business OCR Data

C 93 8 Updated Jan 27, 2025

Enumerate Windows Defender threat families and dump their names according category

C 88 27 Updated May 27, 2019

This repo will contain the core detection, only for Cobaltstrike's leaked versions. Non-leaked version detections wont be shared

C 88 10 Updated Oct 12, 2023

List the ETW provider(s) in the registration table of a process.

C 52 9 Updated Sep 20, 2023

This tool have the power to hide any PID/directory in the Linux kernel

C 22 5 Updated Sep 13, 2024

Combining Sealighter with unpatched exploits to run the Threat-Intelligence ETW Provider

C 1 Updated Dec 6, 2022

Simple (relatively) things allowing you to dig a bit deeper than usual.

C 1 Updated Jan 14, 2024

Snoopy Command Logger is a small library that logs all program executions on your Linux/BSD system.

C 1 Updated Sep 13, 2023

LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, such as those powered by Android. The tool supports acquir…

C 1 Updated Apr 21, 2023