Live, system-wide USB transfer sniffer in eBPF — decodes USB traffic inline (control SETUP, SCSI, HID) from two universal URB hooks. No usbmon, no hardware sniffer. CO-RE portable.
☆86Aug 10, 2026Updated 2 weeks ago
Alternatives and similar repositories for usbsnoop
Users that are interested in usbsnoop are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- htop for the airwaves — a live 802.11 (Wi-Fi) RF dashboard in your terminal☆59Aug 10, 2026Updated 2 weeks ago
- Live terminal Redis traffic profiler built on eBPF. Ranks key patterns, flags footguns, reads TLS.☆25Aug 21, 2026Updated last week
- IoT Firmware Deep Analysis: Automated reverse engineering and vulnerability discovery for IoT firmware binaries.☆43Updated this week
- A PoC Cobalt Strike UDRL written in Rust☆34Jun 20, 2026Updated 2 months ago
- Automatically deploying Mythic C2 in Azure using Terraform☆25Jul 3, 2026Updated last month
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification s…☆42Jun 4, 2026Updated 2 months ago
- .NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on dis…☆41Jul 13, 2026Updated last month
- A vibe-coded port of wiretap☆36Apr 25, 2026Updated 4 months ago
- tail -f for signals. Every signal any process on the box raises — who sent it, who it hit, which signal, how it was raised (kill(2), the …☆159Aug 10, 2026Updated 2 weeks ago
- Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !☆44Mar 24, 2026Updated 5 months ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 4 months ago
- Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advance…☆116Jun 30, 2026Updated 2 months ago
- Linux LPE - Reliable Jail/Container Escape☆54Jun 29, 2026Updated 2 months ago
- docker ps that you can actually walk around in. Every running container on the host as a live table — arrow into any one and get a full, …☆74Aug 10, 2026Updated 3 weeks ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆16Jan 26, 2023Updated 3 years ago
- executing shellcode directly from a python variable☆30Dec 20, 2025Updated 8 months ago
- Thermal pocket printer - BLE protocol reverse engineering, Python CLI, and web GUI☆18May 4, 2026Updated 3 months ago
- A Windows x64 offensive research framework that constructs fully synthetic call stacks☆70Jul 14, 2026Updated last month
- Tailscale/Headscale C2 profile and agent for Mythic☆34Mar 14, 2026Updated 5 months ago
- The samples referenced in my book, Evasive Malware (No starch Press)☆62Feb 20, 2026Updated 6 months ago
- Phantom-Evasion-Loader is a standalone, pure x64 Assembly injection engine engineered to minimize the detection surface of modern EDR/XDR…☆110Aug 8, 2026Updated 3 weeks ago
- A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++☆265Jun 18, 2026Updated 2 months ago
- MCP server for automated binary diffing.☆19Jul 15, 2026Updated last month
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Smuggling C2 comms through links previews☆18Jun 17, 2026Updated 2 months ago
- CVE-2025-59501 POC code☆25Nov 20, 2025Updated 9 months ago
- top, but for the HTTP endpoints on your host — a live dashboard of the most active plaintext HTTP endpoints, right in the terminal.☆223Aug 10, 2026Updated 2 weeks ago
- A cross-platform tool to find traces of old SIDs remaining in LDAP objects of the Active Directory☆26Jun 29, 2025Updated last year
- ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you qu…☆25Jul 16, 2026Updated last month
- In-depth reverse engineering of a suspected LockBit affiliate dropper, documenting shellcode loading, import polymorphism, and payload de…☆15Jan 24, 2026Updated 7 months ago
- ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.☆33Apr 12, 2026Updated 4 months ago
- Cross-platform FPV decoding and visualization☆79Jun 30, 2026Updated 2 months ago
- A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.☆103Jul 16, 2026Updated last month
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- OSINT intelligence on any IP, domain, or ASN☆19Jun 20, 2026Updated 2 months ago
- Parses cached certificate templates from a Windows Registry file and displays them in the same style as Certipy does☆96Jul 3, 2025Updated last year
- A simple C2 Framework written in modern C++☆32Jul 2, 2026Updated last month
- Curated Linux LPE corpus — 28 modules from 2016 to 2026, with detection rules. One command, safest-first root: skeletonkey --auto --i-kno…☆25Jul 24, 2026Updated last month
- ☆20Jul 5, 2026Updated last month
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆27May 21, 2026Updated 3 months ago
- This repository contains the research tool presented at x33fcon 2026, along with the associated presentation slides. The content is made …☆65Jun 15, 2026Updated 2 months ago