Skip to content
View koutto's full-sized avatar

Block or report koutto

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 250 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

C 1,756 229 Updated Nov 3, 2024

LLVM plugin to transparently apply stack spoofing and indirect syscalls to Windows x64 native calls at compile time.

C 317 35 Updated Jan 17, 2024
C++ 120 15 Updated May 12, 2021

modify from memorymodule. support exception

C 219 97 Updated Oct 22, 2020
C++ 161 32 Updated Dec 30, 2022

Stand up a simple Elastic container with Kibana, Fleet, and the Detection Engine

Shell 481 88 Updated May 7, 2025

BOF for Kerberos abuse (an implementation of some important features of the Rubeus).

C 496 55 Updated Mar 29, 2025

The fastest and more comprehensive multiprotocol credentials bruteforcer / password sprayer and enumerator. 🥷

Rust 1,729 110 Updated Sep 18, 2025

Gather and update all available and newest CVEs with their PoC.

HTML 7,253 915 Updated Sep 29, 2025

jsleak is a tool to find secret , paths or links in the source code during the recon.

Go 544 56 Updated Sep 25, 2025

LDAP enumeration tool implemented in Python3

Python 224 31 Updated May 20, 2025

Free, libre, effective, and data-driven wordlists for all!

628 85 Updated Sep 10, 2021

Execute unmanaged Windows executables in CobaltStrike Beacons

C 697 105 Updated Mar 4, 2023

Use hardware breakpoints to spoof the call stack for both syscalls and API calls

C 197 28 Updated Jun 6, 2024

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

C 604 63 Updated Sep 26, 2023

HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.

C++ 692 106 Updated Jul 19, 2023

Privileger is a tool to work with Windows Privileges

C++ 138 33 Updated Feb 7, 2023

Obfuscate powershell scripts by replacing Function names, Variables and Parameters.

Python 519 107 Updated Nov 26, 2022

Creating a repository with all public Beacon Object Files (BoFs)

526 58 Updated Aug 30, 2023

AppSec Ezine Public Repository.

1,193 104 Updated Sep 26, 2025

A wrapper around grep, to help you grep for things

Go 2,018 337 Updated Jun 8, 2024

A fast, simple, recursive content discovery tool written in Rust.

Rust 6,999 552 Updated Sep 28, 2025

Kubernetes exploitation tool

Go 363 21 Updated Jul 26, 2024

Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs

Go 1,225 166 Updated Aug 18, 2023
Python 248 30 Updated Dec 16, 2022

x64 binary obfuscator

C++ 1,895 273 Updated Jul 14, 2023

Active Directory data ingestor for BloodHound Legacy written in Rust. 🦀

Rust 1,073 106 Updated Oct 21, 2024

Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing programmatical access in the VBA object environmen…

Go 747 130 Updated Aug 18, 2023