Skip to content
View darmado's full-sized avatar
😀
😀

Block or report darmado

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 250 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
42 results for source starred repositories written in C
Clear filter

Small and highly portable detection tests based on MITRE's ATT&CK.

C 11,046 2,971 Updated Sep 29, 2025

ClamAV - Documentation is here: https://docs.clamav.net

C 5,624 791 Updated Sep 26, 2025

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters

C 4,211 711 Updated Jul 8, 2025

eBPF-based Security Observability and Runtime Enforcement

C 4,183 460 Updated Sep 30, 2025

fake keyboard/mouse input, window management, and more

C 3,576 324 Updated Jan 11, 2025

A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)

C 3,440 493 Updated Jul 21, 2025

Simple (relatively) things allowing you to dig a bit deeper than usual.

C 3,405 551 Updated Aug 11, 2025

generate CobaltStrike's cross-platform payload

C 2,501 367 Updated Nov 20, 2023

A post exploitation framework designed to operate covertly on heavily monitored environments

C 2,155 334 Updated Sep 29, 2021

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

C 1,993 358 Updated May 28, 2025

Situational Awareness commands implemented using Beacon Object Files

C 1,574 256 Updated Sep 22, 2025

Windows Privilege Escalation from User to Domain Admin.

C 1,415 218 Updated Dec 18, 2022

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

C 1,362 259 Updated Nov 22, 2023

Dump cookies and credentials directly from Chrome/Edge process memory

C 1,336 124 Updated Sep 19, 2025

Research code & papers from members of vx-underground.

C 1,299 250 Updated Dec 7, 2021

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

C 1,295 208 Updated Oct 27, 2023

HVNC for Cobalt Strike

C 1,271 191 Updated Dec 7, 2023

Collection of PoC and offensive techniques used by the BlackArrow Red Team

C 1,135 188 Updated Jul 19, 2024

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vanity-a-new-approach-to-code-injection--edr-bypass…

C 658 88 Updated Dec 23, 2022

A BOF that runs unmanaged PEs inline

C 655 80 Updated Oct 23, 2024

Collection of Beacon Object Files (BOF) for Cobalt Strike

C 644 92 Updated Aug 15, 2025

Evade sysmon and windows event logging

C 625 115 Updated Apr 8, 2020

Inject .NET assemblies into an existing process

C 504 74 Updated Jan 19, 2022

Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North Korean APT InkySquid / ScarCruft / APT37. TTP: Use Mi…

C 489 99 Updated May 16, 2023

Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll

C 478 55 Updated Feb 3, 2022

PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.

C 431 49 Updated Jun 15, 2024

An other No-Fix LPE, NTLMRelay2Self over HTTP (Webdav).

C 414 43 Updated Jan 27, 2024
Next