+
Skip to content
View RistBS's full-sized avatar

Block or report RistBS

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer

C++ 503 78 Updated Feb 13, 2024
C++ 263 318 Updated Feb 19, 2018

Have fun with the LowFragmentationHeap

C++ 241 44 Updated Feb 3, 2021

Windows 10 PE image loader (LDR) NTDLL component toolbox

C 49 12 Updated Oct 22, 2019

Tooling to generate metadata for Win32 APIs in the Windows SDK.

C++ 1,402 134 Updated Jun 11, 2025

Small application that can be used to log loader snaps and other debug output

C++ 68 8 Updated Jan 18, 2024

A BOF that runs unmanaged PEs inline

C 629 78 Updated Oct 23, 2024

LOJAX ROOTKIT (UEFI) +PDF Included[x]

34 16 Updated Mar 9, 2023

Unlicensed tiny / small portable implementation of 128/256-bit AES encryption in C, x86, AMD64, ARM32 and ARM64 assembly

C 129 28 Updated Apr 19, 2025

Enumerate various traits from Windows processes as an aid to threat hunting

C++ 187 34 Updated Jan 13, 2022

See the Wiki for more information

C++ 5 Updated Oct 25, 2021

WinDBG Anti-RootKit Extension

C++ 634 180 Updated Jul 29, 2020

利用EFSRPC协议批量探测出网

Python 66 2 Updated Oct 12, 2023

For when DLLMain is the only way

C 389 65 Updated Oct 29, 2024

A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.

C 562 66 Updated Jan 2, 2025
C 2 Updated Nov 3, 2023

Autonomous pre-boot DMA attack hardware implant for M.2 slot based on PicoEVB development board

C 86 15 Updated Oct 21, 2023

Updated version of System Management Mode backdoor for UEFI based platforms: old dog, new tricks

C 324 53 Updated Nov 3, 2023
C 7 5 Updated Mar 28, 2025

Hardcore Debugging

901 112 Updated Apr 24, 2025

Persistence via Shell Extensions

C++ 62 8 Updated Aug 4, 2023

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.

Python 66 8 Updated Oct 13, 2024

Explore Kernel Objects on Windows

C++ 219 39 Updated Apr 4, 2025

Signtool for expired certificates

C++ 482 53 Updated Jun 10, 2023

Resolve DOS MZ executable symbols at runtime

C++ 95 24 Updated Nov 12, 2021

Small tool to play with IOCs caused by Imageload events

C++ 42 8 Updated May 14, 2023

yet another sleep encryption thing. also used the default github repo name for this one.

C 69 14 Updated May 11, 2023

clone of armadillo patched for windows

C 47 12 Updated Oct 22, 2024
Next
点击 这是indexloc提供的php浏览器服务,不要输入任何密码和下载