Skip to content
View VirtualAlllocEx's full-sized avatar
🏠
Working from home
🏠
Working from home

Sponsoring

@BC-SECURITY

Highlights

  • Pro

Block or report VirtualAlllocEx

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Evasive shellcode loader

C++ 398 65 Updated Oct 17, 2024

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by performing on-the-fly decryption of individual encry…

C++ 591 85 Updated Jun 12, 2024

Windows Local Privilege Escalation Cookbook

PowerShell 1,260 194 Updated Jan 20, 2025

Payload Generation Framework

VBA 98 14 Updated Mar 16, 2024

An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer

C++ 539 81 Updated Feb 13, 2024

A little tool to play with Windows security

C 21,218 4,026 Updated May 11, 2025

This repository contains sample programs written primarily in C and C++ for learning native code reverse engineering.

C 730 109 Updated Nov 30, 2025

This repository contains sample programs that mimick behavior found in real-world malware. The goal is to provide source code that can be compiled and used for learning purposes, without having to …

C 684 83 Updated Jul 6, 2024

DLL Unlinking from InLoadOrderModuleList, InMemoryOrderModuleList, InInitializationOrderModuleList, and LdrpHashTable

Nim 58 14 Updated Dec 15, 2023

PoC Implementation of a fully dynamic call stack spoofer

C++ 901 108 Updated Jul 20, 2024

C++ self-Injecting dropper based on various EDR evasion techniques.

C 425 70 Updated Feb 11, 2024

Utilizing hardware breakpoints to evade monitoring by Endpoint Detection and Response platforms

C++ 134 21 Updated Dec 20, 2022

Shellcode Loader Implementing Indirect Dynamic Syscall , API Hashing, Fileless Shellcode retrieving using Winsock2

C++ 293 50 Updated Jul 15, 2023

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

Rust 259 43 Updated Jun 29, 2024

OSCP 2023 Preparation Guide | Courses, Tricks, Tutorials, Exercises, Machines

1,072 234 Updated Jan 25, 2026

Remote Shellcode Injector

C++ 221 40 Updated Aug 27, 2023

Security product hook detection

C++ 323 48 Updated Mar 30, 2021

HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.

C++ 717 108 Updated Jul 19, 2023

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

PowerShell 2,693 521 Updated Jul 6, 2025

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

Python 1,577 198 Updated Jul 31, 2024

Intro to x86 Assembly Language.

Assembly 287 58 Updated Apr 29, 2020

The Havoc Framework

Go 8,138 1,168 Updated Dec 18, 2025

Powershell script to do domain auditing automation

PowerShell 404 107 Updated Jan 8, 2026

Audit tool for Active Directory. Automates a lot of checks from a pentester perspective.

PowerShell 175 40 Updated Jul 7, 2025

Cheatsheet for the commands learned in Attack and Defense Active Directory Lab

240 71 Updated Dec 4, 2022

Pentesting cheatsheet with all the commands I learned during my learning journey. Will try to to keep it up-to-date.

C++ 1,494 250 Updated Nov 21, 2025

Stealing Signatures and Making One Invalid Signature at a Time

Python 2,363 487 Updated Aug 11, 2021
Next