Skip to content
View AlpacaOrz's full-sized avatar

Block or report AlpacaOrz

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Hook system calls, context switches, page faults and more.

C++ 2,458 500 Updated May 9, 2023

eBPF implementation that runs on top of Windows

C 3,007 244 Updated Jan 18, 2025

C++ wrapper for libzip

C++ 401 96 Updated Dec 10, 2024

Principled, lightweight C/C++ PE parser

C++ 812 156 Updated Nov 27, 2024

A C library for reading, creating, and modifying zip archives.

C 872 279 Updated Jan 8, 2025

Freeze (package) Python programs into stand-alone executables

Python 12,063 1,953 Updated Jan 17, 2025

PyInstaller Extractor

Python 3,107 630 Updated Nov 12, 2024

Malware Development for Ethical Hackers, published by Packt

C 262 50 Updated Nov 30, 2024

A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware. Brought to you by Winsider Seminars & Solutions, Inc. @ http://www.windows-internals…

C 11,298 1,421 Updated Jan 19, 2025

CWE-781: Improper Address Validation in IOCTL with METHOD_NEITHER I/O Control Code

C 331 63 Updated Jul 4, 2024

Document ETW providers

C 216 50 Updated Mar 28, 2020

Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a library from memory into a host process.

C 2,805 778 Updated Sep 3, 2022

Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form.

C++ 5,401 1,027 Updated Oct 9, 2024

Sandboxie Plus & Classic

C 14,273 1,596 Updated Jan 19, 2025

Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.

C 288 60 Updated Apr 16, 2024

ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.

C# 297 69 Updated Mar 20, 2024

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

C++ 3,189 441 Updated Dec 14, 2024

Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It is derived from ByteDance's internal best practi…

Go 2,311 450 Updated Jan 17, 2025

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

Go 11,743 1,614 Updated Jan 6, 2025