Skip to content
View lupingQAQ's full-sized avatar
🤩
Focusing
🤩
Focusing

Block or report lupingQAQ

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
lupingQAQ/README.md

lupingQAQ

Offensive Security Researcher · Red Team Operator

Red team operations, from initial access to long-hold persistence.

Focus AD C2 Evasion Cloud AI Java


Projects

Stars Docs

A 24-chapter full-stack offensive security reference: anti-attribution, reconnaissance, penetration testing, code audit, post-exploitation and AD lateral movement, phishing, C2 development, AV/EDR evasion, cloud-native attacks, and AI-powered offense. Updated with 2025-2026 APT techniques.

English + Chinese, with a searchable docs site and the original XMind mind map.

Stars Docs

Write your own AD PoC with impacket: source-level guides to Kerberos, DCE/RPC, DCOM and WMI programming. Bilingual (EN/ZH) with PDF editions, built from real domain-penetration development work.


Stars License

Autonomous agent that mines Java deserialization gadget chains from any JAR directory — static bytecode analysis + dynamic JVM probes + dual-model adversarial auditing → weaponized PoC. One command, zero intermediate decisions: JARs in → chains + PoCs out. Includes interactive TUI (EN/CN) and CLI modes. 8 novel chains discovered (1 T1 entry + 6 T2 carriers).

English + Chinese README.


Currently

  • Tracking 2025-2026 offensive techniques: ADCS ESC1-ESC16, eBPF rootkits, sleep obfuscation, device-code phishing, AI infrastructure CVEs
  • Maintaining both references above, bilingual, release-driven

WeChat MP: IndexSec

All published work is for lawful security research, education, and authorized testing.

Pinned Loading

  1. impacket-programming-manual impacket-programming-manual Public

    impacket programming manual and tutorial — write your own AD PoC with Kerberos/RPC/DCOM/WMI source-level guides (中英双语+PDF)

    107 16

  2. red-team-skill-tree red-team-skill-tree Public

    Red team skill tree — full-stack offensive security reference: recon, AD attacks, C2 development, AV/EDR evasion, cloud-native & AI-powered attacks. 红队全栈技能参考(蓝军技能树)

    3

  3. JGD JGD Public

    Autonomous agent that mines Java deserialization gadget chains from any JAR directory. Static bytecode analysis + dynamic JVM probes + dual-model adversarial auditing → weaponized PoC. Solving the …

    Python

  4. SqlStealthRogue SqlStealthRogue Public

    Zero-probe, high-speed SQL/NoSQL injection data dumper. 12 engines verified, tamper-plugin WAF bypass, every request is an extraction request. 让天底下没有难拖的数据库。

    Python 1