Collection of custom implementations about some WinAPI functions
☆38Jul 30, 2026Updated 2 months ago
Alternatives and similar repositories for UPrimitives
Users that are interested in UPrimitives are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A EDR bypassing shellcode loader framework for Windows 10 64bit, featuring ETW/AMSI patching, Tartarus Gate, process protection and more☆96Jun 24, 2026Updated 3 months ago
- PPLReaper is a Windows UNSIGNED kernel driver + userland companion tool designed to inspect and manipulate Protected Process Light (PPL) …☆25Mar 4, 2026Updated 6 months ago
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆29May 21, 2026Updated 4 months ago
- A PoC Cobalt Strike UDRL written in Rust☆34Sep 12, 2026Updated 3 weeks ago
- Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification s…☆42Jun 4, 2026Updated 3 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Async port/ping scanner BOF. Supports IP/port ranges, CIDR notation and hostnames.☆17Jul 23, 2026Updated 2 months ago
- test☆107Apr 25, 2026Updated 5 months ago
- Polymorphic AV/AMSI bypass toolkit - Donut shellcode runner for offensive .NET/PE tools☆36May 26, 2026Updated 4 months ago
- WinDbg x64 extension that disassembles live functions and uses an LLM to produce verified pseudocode.☆111Jun 22, 2026Updated 3 months ago
- windows api bug☆38May 24, 2026Updated 4 months ago
- Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browser…☆261May 18, 2026Updated 4 months ago
- Async BOF that monitors USB device connect/disconnect events, reports device information and performs actions on connected USB storage vo…☆57Jul 23, 2026Updated 2 months ago
- Find Windows RWX Memory Regions depending on the memory space needed☆18Nov 26, 2023Updated 2 years ago
- M365 Conditional Access Policy Bypass OST (Offensive Tooling)☆50Apr 22, 2026Updated 5 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- CVE-2026-23631 (DarkReplica) Redis Exploit☆33Jun 2, 2026Updated 4 months ago
- Windows named pipe hooking toolkit☆46Mar 20, 2026Updated 6 months ago
- Supporting PoCs and scripts for my talk "OverLAPS: Overriding LAPS Logic"☆24Oct 12, 2025Updated 11 months ago
- Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advance…☆119Sep 17, 2026Updated 2 weeks ago
- NØW is a word-based shellcode encoding and obfuscation tool that transforms raw shellcode bytes into natural-looking English prose.☆92Jun 24, 2026Updated 3 months ago
- Manage Shadows Copies via the VSS API using C#, C++, Crystal or Python. Working on Windows 11☆87Jan 26, 2026Updated 8 months ago
- Collection of Win32 with C++/Assembly for Hooking, Patch and Reversing PE file☆18Nov 7, 2022Updated 3 years ago
- Pink BRC4 skin/theme.☆15Sep 20, 2024Updated 2 years ago
- C++ tool and library for converting .bin files to shellcode in multiple output formats.☆34Aug 4, 2026Updated last month
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Automated script for obfuscating, rebranding and renaming the Havoc C2 Framework to evade AV/EDR and C2 hunters.☆49Aug 13, 2025Updated last year
- Microsoft Vulnerable Driver Block Lists in CSV and JSON for SIEM lookups☆55Sep 15, 2026Updated 2 weeks ago
- Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.☆65Mar 2, 2026Updated 7 months ago
- This extension provides Microsoft Macro Assembler language support for Visual Studio Code☆13Feb 24, 2021Updated 5 years ago
- PDF Icon File Type Spoofer☆17Jul 8, 2024Updated 2 years ago
- Lists of independent cybersecurity blogs covering threat intelligence, purple team, red team, threat hunting, and detection engineering. …☆43Sep 15, 2026Updated 2 weeks ago
- A Windows x64 offensive research framework that constructs fully synthetic call stacks☆73Jul 14, 2026Updated 2 months ago
- ☆60Oct 24, 2024Updated last year
- Querying And Deleting Shadow Copies Using The IOCTL_VOLSNAP_QUERY_NAMES_OF_SNAPSHOTS & IOCTL_VOLSNAP_DELETE_SNAPSHOT IOCTLs☆22Aug 7, 2025Updated last year
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- BOF to terminate a process via PID as argument☆27Sep 7, 2025Updated last year
- Living Off the Land Credentials. Public credential defaults, locations, and exposure patterns for real products, SaaS/cloud services, app…☆60Jul 19, 2026Updated 2 months ago
- Intel 64/Windows low-level experiments☆118Sep 16, 2026Updated 2 weeks ago
- This repo contains PoCs for vulnerable Windows drivers.☆153Dec 20, 2025Updated 9 months ago
- ☆18Dec 11, 2025Updated 9 months ago
- NSecSoftBYOVD POC☆62Feb 12, 2026Updated 7 months ago
- Bof of RegPwn by MDSec☆129Mar 15, 2026Updated 6 months ago