Lists (4)
Sort Name ascending (A-Z)
Stars
A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.
PIC shellcode agent based on Stardust framework and Crystal Palace
Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits
Run unsigned kernel payloads in a signed kernel driver via wasm3. No JIT/W^x (HVCI/etc., compliant)
A vibe coded file encryptor/decryptor entirely generated by local AI
Sleep replacement that executes real, varied work to break behavioral pattern matching by EDR and anti-cheat systems
Workshop materials for “Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel” presented at DEF CON 34 and BSidesLV 2026. Covers malware development, EDR Architecture, EDR evasio…
POC tool for ResetNightmare (CVE-2026-27912)
Cloak, Honey, Trap: Proactive Defenses Against LLM Agents
Hunt down social media accounts by username across social networks
The all-in-one offensive tool suite for all things Flock Safety. Built from the 55 vulnerabilities Jon 'GainSec' Gaines found across Flock Safety's Raven (Gunshot Detection), Picard/Bravo (Edge Com…
Defensive static analysis and detection engineering for the 2026 Shai-Hulud npm supply-chain campaign: Sigma/YARA rules, IOCs, ATT&CK mapping, and defender guidance.
📚 Learn to write an embedded OS in Rust 🦀
A curated list of awesome Claude Skills, resources, and tools for customizing Claude AI workflows
This repository contains my complete resources and coding practices for malware development using Rust 🦀.
Windows native ETW inspection suite for browsing providers, reading metadata, consuming live events, recording ETL traces, filtering results, and inspecting ETL/JSON/CSV recordings from one desktop…
Find, verify, and analyze leaked credentials
AI agent skill that researches any topic across Reddit, X, YouTube, HN, Polymarket, and the web - then synthesizes a grounded summary
Open-source LLM red-teaming technique toolkit (162 transforms, 36 mutators, 25 tool surfaces). MIT.
Misconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive and hardening guidance.
Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET assembli…
A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Develo…
Top disclosed reports from HackerOne
OpenHuman is an open source agent harness with local-first memory, agent orchestration, and workflows