Skip to content
View hxnoyd's full-sized avatar

Block or report hxnoyd

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Sensor Mappings to ATT&CK is a collection of resources to assist cyber defenders with understanding which sensors and events can help detect real-world adversary behaviors in their environments.

Python 54 4 Updated Jun 21, 2025

Collection of Windows Privilege Escalation (Analyse/PoC/Exploit)

474 84 Updated Nov 19, 2024

A method of bypassing EDR's active projection DLL's by preventing entry point exection

C# 1,173 165 Updated Mar 31, 2021

Process Monitor X v2

C++ 661 131 Updated Jul 4, 2026

Adversarial Interception Mission Oriented Discovery and Disruption Framework, or AIMOD2, is a structured threat hunting approach to proactively identify, engage and prevent cyber threats denying or…

HTML 91 10 Updated Sep 16, 2023

Windows Event Log Killer

C 1,811 305 Updated Sep 21, 2023

RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, it first collects the syscall numbers of the NtOpenFile, NtC…

C++ 499 108 Updated Jan 25, 2022

A Pin Tool for tracing API calls etc

C++ 1,674 167 Updated Jun 2, 2026

Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation of detective controls with the goal of proactively identifyin…

1,307 139 Updated Jul 23, 2026

Pointing cybersecurity teams to thousands of detection rules and offensive security tests aligned with common attacker techniques

JavaScript 143 27 Updated Feb 25, 2024

book for parents and kids.

Python 660 54 Updated Aug 30, 2025

Malware development for red teaming workshop

C# 227 42 Updated Nov 15, 2021

ATTiRe logging for Invoke-Atomicredteam

PowerShell 8 5 Updated Jun 1, 2023

Attack Tool Timing and Reporting - Structured Attack Logging Format

22 4 Updated Nov 4, 2022

The Github project for The Defender's Guide by Luke Paine and Jonathan Johnson

160 16 Updated Jun 15, 2023

The swiss army knife of LSASS dumping

C 2,129 271 Updated Sep 17, 2024

Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.

2,944 393 Updated Jul 29, 2026

Project for tracking publicly disclosed DLL Hijacking opportunities.

926 117 Updated Jul 28, 2026

PoCs and tools for investigation of Windows process execution techniques

C# 957 147 Updated Feb 2, 2026

Collection of KQL queries

1,644 382 Updated Jan 29, 2026

⬆️ ☠️ 🔥 Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock

Go 7,161 703 Updated Mar 12, 2024

Threat Hunting queries for various attacks

248 31 Updated Jan 16, 2026

An analytical framework for network traffic and behavioral analytics

Python 457 88 Updated Dec 7, 2022

Offensive tooling notes and experiments in AutoIt v3 (https://www.autoitscript.com/site/autoit/)

AutoIt 451 59 Updated Feb 24, 2022

This Powershell script will generate a malicious Microsoft Office document with a specified payload and persistence method.

PowerShell 687 208 Updated Oct 27, 2016

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

Rust 3,269 285 Updated Jul 29, 2026

A Docker based LDAP RCE exploit demo for CVE-2021-44228 Log4Shell

Java 72 33 Updated Dec 21, 2022
Next