Skip to content
View hxnoyd's full-sized avatar

Block or report hxnoyd

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Sensor Mappings to ATT&CK is a collection of resources to assist cyber defenders with understanding which sensors and events can help detect real-world adversary behaviors in their environments.

Python 54 4 Updated Jun 21, 2025

Collection of Windows Privilege Escalation (Analyse/PoC/Exploit)

471 82 Updated Nov 19, 2024

A method of bypassing EDR's active projection DLL's by preventing entry point exection

C# 1,168 164 Updated Mar 31, 2021

Process Monitor X v2

C++ 656 129 Updated Jan 22, 2024

Adversarial Interception Mission Oriented Discovery and Disruption Framework, or AIMOD2, is a structured threat hunting approach to proactively identify, engage and prevent cyber threats denying or…

HTML 90 10 Updated Sep 16, 2023

Windows Event Log Killer

C 1,806 304 Updated Sep 21, 2023

RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, it first collects the syscall numbers of the NtOpenFile, NtC…

C++ 500 108 Updated Jan 25, 2022

A Pin Tool for tracing API calls etc

C++ 1,666 166 Updated Jun 2, 2026

Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation of detective controls with the goal of proactively identifyin…

1,213 123 Updated Jun 18, 2026

Pointing cybersecurity teams to thousands of detection rules and offensive security tests aligned with common attacker techniques

JavaScript 142 27 Updated Feb 25, 2024

book for parents and kids.

Python 657 54 Updated Aug 30, 2025

Malware development for red teaming workshop

C# 226 42 Updated Nov 15, 2021

ATTiRe logging for Invoke-Atomicredteam

PowerShell 8 5 Updated Jun 1, 2023

Attack Tool Timing and Reporting - Structured Attack Logging Format

22 4 Updated Nov 4, 2022

The Github project for The Defender's Guide by Luke Paine and Jonathan Johnson

160 16 Updated Jun 15, 2023

The swiss army knife of LSASS dumping

C 2,119 268 Updated Sep 17, 2024

Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.

2,920 389 Updated Jun 12, 2026

Project for tracking publicly disclosed DLL Hijacking opportunities.

918 114 Updated Jun 14, 2026

PoCs and tools for investigation of Windows process execution techniques

C# 960 147 Updated Feb 2, 2026

Collection of KQL queries

1,643 381 Updated Jan 29, 2026

⬆️ ☠️ 🔥 Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock

Go 7,144 705 Updated Mar 12, 2024

Threat Hunting queries for various attacks

246 31 Updated Jan 16, 2026

An analytical framework for network traffic and behavioral analytics

Python 457 88 Updated Dec 7, 2022

Offensive tooling notes and experiments in AutoIt v3 (https://www.autoitscript.com/site/autoit/)

AutoIt 449 60 Updated Feb 24, 2022

This Powershell script will generate a malicious Microsoft Office document with a specified payload and persistence method.

PowerShell 685 207 Updated Oct 27, 2016

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

Rust 3,212 276 Updated Jun 19, 2026

A Docker based LDAP RCE exploit demo for CVE-2021-44228 Log4Shell

Java 72 33 Updated Dec 21, 2022
Next