Skip to content
View rabbitstack's full-sized avatar

Block or report rabbitstack

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Stealthy .NET assembly loading using AssemblyNative::LoadFromBuffer

C# 38 5 Updated Mar 22, 2026

Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities

C 152 4 Updated Mar 25, 2026

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

JavaScript 108,146 14,111 Updated Mar 25, 2026

A Cobalt Strike RL built with Crystal Palace — module overloading, NtContinue entry transfer, call stack spoofing, sleep masking, and static signature removal.

C 172 29 Updated Mar 15, 2026

We took PersistenceSniper, merged it with Python, and misspelled it on purpose. Meet PyrsistenceSniper.

Python 74 7 Updated Mar 22, 2026

A small experiment on assigning a processes threads a specific CPU and then blocking it with a high priority thread

C 32 2 Updated Sep 24, 2025

Project for generating and identifying deceptive LNK files.

Python 307 42 Updated Mar 8, 2026

AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64

Python 386 46 Updated Mar 7, 2026

eBPF-powered silent observer for containerized runtimes, built for malware analysis sandboxes and Agentic AI monitoring.

C 84 9 Updated Mar 9, 2026

practice made claude perfect

HTML 22,021 1,911 Updated Mar 25, 2026

Iosevka configuration to mimic the look and feel of Berkeley Mono as closely as possible.

763 30 Updated Mar 20, 2026

Inter-binary control flow graphing

Python 38 3 Updated Feb 25, 2026

Tools for interacting with authentication packages using their individual message protocols

C++ 424 35 Updated Mar 1, 2026

Tips and tricks I use to optimize my experience with Claude Code.

10 1 Updated Feb 16, 2026

Audiodg.exe DLL hijacking for LPE with reboot-free restart primitive. Executes code as LOCAL SERVICE, escalates to SYSTEM via Scheduled Tasks.

C++ 91 15 Updated Jan 24, 2026
C++ 80 12 Updated Feb 12, 2026

Database diagrams editor that allows you to visualize and design your DB with a single query.

TypeScript 21,675 1,310 Updated Mar 21, 2026

Rust Windows EDR (user-mode, no driver): ETW → Sysmon-style normalization → Sigma/Yara/IOC detection → ECS NDJSON alerts.

Rust 100 16 Updated Mar 4, 2026

Triage automation tool

Python 22 1 Updated Mar 12, 2026

A curated list of funding programs supporting the awesome work of Open Source maintainers.

55 2 Updated Mar 12, 2026

An ultra-simplified explanation to design patterns

47,652 5,508 Updated Dec 2, 2024
C++ 50 8 Updated Nov 7, 2024

The different ways to dump lsass

C 280 36 Updated Aug 15, 2025

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

C++ 47 3 Updated Jan 28, 2026

Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from modern Chromium-based and Gecko-based browsers …

C 660 96 Updated Feb 14, 2026

This map lists the essential techniques to bypass anti-virus and EDR

3,177 349 Updated Mar 28, 2025

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

C++ 1,025 199 Updated Aug 29, 2023

Demonstrates consuming from a SecurityTrace ETW session by consuming from the Threat-Intelligence ETW provider without a driver or PPL privilege

C++ 72 12 Updated Jan 19, 2026

A proof-of-concept to demonstrate randomized execution paths and their impact on call stack signatures — ideal for EDR testing, behavior-based detection research, and evasion analysis.

C++ 24 3 Updated Jan 17, 2026

Example of call stack spoofing trough the construction of syntetic frames and stack manipulation

C++ 32 6 Updated Jan 17, 2026
Next