Skip to content
View cr1me0's full-sized avatar

Block or report cr1me0

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

31 stars written in C
Clear filter

A little tool to play with Windows security

C 19,432 3,726 Updated Jul 5, 2024

Defeating Windows User Account Control

C 6,362 1,322 Updated Jul 22, 2024

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters

C 3,585 635 Updated Oct 23, 2024

Simple (relatively) things allowing you to dig a bit deeper than usual.

C 3,204 525 Updated Nov 3, 2024

Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a library from memory into a host process.

C 2,748 777 Updated Sep 3, 2022

generate CobaltStrike's cross-platform payload

C 2,276 344 Updated Nov 20, 2023

各种CMS、各种平台、各种系统、各种软件漏洞的EXP、POC ,该项目将持续更新

C 2,047 812 Updated Sep 12, 2023

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

C 1,646 397 Updated Nov 1, 2024

Fileless lateral movement tool that relies on ChangeServiceConfigA to run command

C 1,399 236 Updated Jul 10, 2023

Situational Awareness commands implemented using Beacon Object Files

C 1,256 218 Updated Sep 9, 2024

Windows NT Syscall tables

C 1,147 237 Updated Nov 3, 2024

助力每一位RT队员,快速生成免杀木马

C 715 96 Updated Apr 17, 2024

内网域渗透小工具

C 715 130 Updated Apr 20, 2021

在Windows环境下的进程注入方法:远程线程注入、创建进程挂起注入、反射注入、APCInject、SetWindowHookEX注入

C 644 136 Updated Sep 22, 2018

Windows Elevation(持续更新)

C 637 165 Updated Feb 19, 2022

Execute unmanaged Windows executables in CobaltStrike Beacons

C 635 98 Updated Mar 4, 2023

Syscall免杀

C 502 55 Updated Jun 21, 2024

MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly.

C 492 62 Updated Aug 8, 2024

Simulate the behavior of AV/EDR for malware development training.

C 452 37 Updated Feb 15, 2024

Some demos to bypass EDRs or AVs by 78itsT3@m

C 344 59 Updated Jul 6, 2022

一款dump hash工具配合后渗透的利用

C 258 34 Updated Apr 21, 2023

添加计划任务方法集合

C 254 43 Updated Aug 6, 2023

远程创建任务计划工具

C 181 20 Updated Apr 23, 2022

关于RPC一些绕EDR的tips

C 155 37 Updated Mar 3, 2023
C 152 23 Updated Jun 18, 2024

beta

C 111 23 Updated Sep 24, 2024

Seven different DLL injection techniques in one single project.

C 107 420 Updated Jul 21, 2017

Various methods of executing shellcode

C 68 7 Updated Mar 27, 2023

Beacon compiled using clang

C 58 41 Updated Jan 22, 2023
Next