+
Skip to content
View RistBS's full-sized avatar

Block or report RistBS

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer

C++ 520 78 Updated Feb 13, 2024
C++ 265 316 Updated Feb 19, 2018

Have fun with the LowFragmentationHeap

C++ 246 45 Updated Feb 3, 2021

Windows 10 PE image loader (LDR) NTDLL component toolbox

C 49 12 Updated Oct 22, 2019

Tooling to generate metadata for Win32 APIs in the Windows SDK.

C++ 1,428 138 Updated Oct 16, 2025

Small application that can be used to log loader snaps and other debug output

C++ 68 8 Updated Jan 18, 2024

A BOF that runs unmanaged PEs inline

C 657 80 Updated Oct 23, 2024

LOJAX ROOTKIT (UEFI) +PDF Included[x]

34 16 Updated Mar 9, 2023

Unlicensed tiny / small portable implementation of 128/256-bit AES encryption in C, x86, AMD64, ARM32 and ARM64 assembly

C 130 29 Updated Sep 30, 2025

Enumerate various traits from Windows processes as an aid to threat hunting

C++ 189 34 Updated Jan 13, 2022

See the Wiki for more information

C++ 6 Updated Oct 25, 2021

WinDBG Anti-RootKit Extension

C++ 635 181 Updated Jul 29, 2020

利用EFSRPC协议批量探测出网

Python 65 2 Updated Oct 12, 2023

For when DLLMain is the only way

C 402 66 Updated Oct 29, 2024

A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.

C 581 66 Updated Jan 2, 2025
C 2 Updated Nov 3, 2023

Autonomous pre-boot DMA attack hardware implant for M.2 slot based on PicoEVB development board

C 94 16 Updated Oct 21, 2023

Updated version of System Management Mode backdoor for UEFI based platforms: old dog, new tricks

C 341 53 Updated Nov 3, 2023
C 8 5 Updated Aug 25, 2025

Hardcore Debugging

912 114 Updated Sep 7, 2025

Persistence via Shell Extensions

C++ 62 8 Updated Aug 4, 2023

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.

Python 65 8 Updated Oct 13, 2024

Explore Kernel Objects on Windows

C++ 228 41 Updated Apr 4, 2025

Signtool for expired certificates

C++ 490 54 Updated Jun 10, 2023

Resolve DOS MZ executable symbols at runtime

C++ 95 24 Updated Nov 12, 2021

Small tool to play with IOCs caused by Imageload events

C++ 42 8 Updated May 14, 2023

yet another sleep encryption thing. also used the default github repo name for this one.

C 69 14 Updated May 11, 2023

clone of armadillo patched for windows

C 47 12 Updated Oct 22, 2024
Next
点击 这是indexloc提供的php浏览器服务,不要输入任何密码和下载