Skip to content
View rbwdenny's full-sized avatar
🔍
Researching
🔍
Researching
  • RBW
  • Palo Alto

Block or report rbwdenny

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

Multiplayer pivoting solution

Go 519 55 Updated Apr 29, 2026

A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs

Rust 341 44 Updated Feb 27, 2026

WhoAmI by asking the LDAP service on a domain controller.

C# 66 8 Updated Feb 8, 2022

Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration!

C# 942 77 Updated Oct 30, 2025

A *very* imperfect attempt to correlate Kernel32 function calls to native API (Nt/Zw) counterparts/execution flow.

28 8 Updated Dec 16, 2021

SAM Dumping in C#

C# 54 7 Updated Nov 27, 2025

助力每一位RT队员,快速生成免杀木马

C 838 107 Updated Apr 17, 2024

The code is a pingback to the Dark Vortex blog:

C 189 35 Updated Jan 26, 2023

Your Windows syscall hooking factory - feat Canterlot's Gate - All accessible over MCP

Nim 130 14 Updated Jun 4, 2026

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

C++ 1,270 174 Updated Dec 11, 2023

Indirect Syscall implementation to bypass userland NTAPIs hooking.

C 84 7 Updated Aug 13, 2024

Uses Threat-Intelligence ETW events to identify shellcode regions being hidden by fluctuating memory protections

C++ 177 15 Updated May 17, 2023

External Base for researching Shadow Regions in Valorant

C++ 309 91 Updated Mar 16, 2026

Execute shellcode files with rundll32

C++ 222 25 Updated Jan 28, 2024

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

C++ 1,117 163 Updated Jun 17, 2022

Kernel mode to user mode dll injection

C++ 313 28 Updated Apr 10, 2021

The easiest way to run WireGuard VPN + Web-based Admin UI.

TypeScript 26,041 2,481 Updated Jun 12, 2026

Anvilogic Forge

119 8 Updated Mar 31, 2026

Anti-Rootkit/Anti-Cheat Driver to uncover unbacked or hidden kernel code.

C++ 334 41 Updated Mar 12, 2026

Experimental Windows x64 Kernel Rootkit with anti-rootkit evasion features.

C++ 605 90 Updated Aug 2, 2025

A bunch of scripts and code i wrote.

C 150 28 Updated Nov 7, 2024

AICI: Prompts as (Wasm) Programs

Rust 2,075 84 Updated Jan 22, 2025

A massively parallel, high-level programming language

Rust 19,448 480 Updated Jun 3, 2025

A fast compressor/decompressor

C++ 6,577 1,039 Updated May 9, 2026

General malware analysis stuff

Python 37 4 Updated Aug 26, 2024

A simple multiplatform command line search tool for Windows API.

Go 47 5 Updated Mar 7, 2025

A command line Windows API tracing tool for Golang binaries.

C 159 15 Updated Dec 4, 2023

IDA plugin that resolves PPL calls to the actual underlying PPL function.

Python 56 6 Updated Feb 28, 2023

金蝶星空云反序列化漏洞内存马

C# 53 8 Updated Mar 27, 2024
Next