Starred repositories
FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.
Malware Development for Ethical Hackers, published by Packt
Reimplement CreateProcessInternalW via Windows 10 20H1+/Windows 11 Base on NtCreateUserProcess-Post
This project contains Offensive Development solutions in C++ and C#
Windows Internals Book 7th edition Tools
Contains examples for the Spectre.Console library.
A .NET library that makes it easier to create beautiful console applications.
KQL queries for Microsoft Defender Advanced Hunting organized around the TTPs of the MITRE ATT&CK framework.
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build of Windows | Provides tools and Guides for Pers…
A FREE comprehensive reverse engineering tutorial covering x86, x64, 32-bit/64-bit ARM, 8-bit AVR and 32-bit RISC-V architectures.
Welcome to the Just another Kusto hacker ("JAKH") contest!
Building CLI Applications with .NET, published by Packt
A collection of tools Neil and Andy have been working on released in one place and interlinked with previous tools
Covenant is a collaborative .NET C2 framework for red teamers.
SharpGen is a .NET Core console application that utilizes the Rosyln C# compiler to quickly cross-compile .NET Framework console applications or libraries.
Proof of Concept (PoC) .NET tool for remotely killing EDR with WDAC
SharpSploit is a .NET post-exploitation library written in C#
Programmable dynamic firewall API for Windows platform written in C#.
An automated Adversary Emulation lab with terraform and MCP server. Build Caldera techniques and operations assisted with LLMs. Built for IaC stability, consistency, and speed.
A little tool to play with Azure Identity - Azure and Entra ID lab creation tool. Blog: https://medium.com/@iknowjason/sentinel-for-purple-teaming-183b7df7a2f4
A framework for developing alerting and detection strategies for incident response.
A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.
Curated list of resources on HashiCorp's Terraform and OpenTofu
A curated list of tools for incident response. With repository stars⭐ and forks🍴
A curated knowledge base to build, run and mature a SOC (including CSIRT).