
MasterHttpRelayVPN
基于域前置的HTTP/SOCKS5代理隧道,通过Google Apps Script传输流量,具备中间人TLS拦截、HTTP/1-2多路复用和DPI规避功能。

基于域前置的HTTP/SOCKS5代理隧道,通过Google Apps Script传输流量,具备中间人TLS拦截、HTTP/1-2多路复用和DPI规避功能。

一种稍微更有趣的禁用 Windows Defender + 防火墙的方法。(通过 WSC api)

一个用于将 DLL 加载到内存中的小型 x64 库。

Windows x64 kernel mode rootkit process hollowing POC.

Rusty Hypervisor - 使用 Rust 编写的 Windows 内核 Blue Pill Type-2 虚拟机监控器(代号:Matrix)

Cronos 是一款针对 Windows 10/11 x64 的 Ring 0 rootkit。Cronos 能够隐藏进程、保护进程,并通过令牌操作(token manipulation)提升其权限。

Black Angel 是一款 Windows 11/10 x64 内核模式 rootkit。该 Rootkit 可在启用 DSE 的情况下加载,同时保持其全部功能。

Revenant - A 3rd party agent for Havoc that demonstrates evasion techniques in the context of a C2 framework


一个使用自定义类型2虚拟机监控器、eBPF XDP和TC程序的Rust编写的Linux内核rootkit。

LimeRAT | 简单而强大的Windows远程管理工具(RAT)

用于检测利用 CVE-2018-6389 进行潜在攻击的 ModSecurity 规则集

一个被我利用的易受攻击驱动程序(BYOVD),能够终止市场上的几种EDR和防病毒软件,使其失效,同时适用于x32和x64(CVE-2023-44976)。

针对CVE-2026-23918 Apache http2 RCE的检测规则 - 致谢:stringa.ai, isec.pl


针对 Erlang/OTP SSH CVE-2025-32433 的安全研究。

反虚拟化、反调试、反VM、反虚拟机、反调试、反Sandboxie、反沙箱、VM检测包。仅限Windows。