Skip to content
View mthcht's full-sized avatar
🏠
Working from home
🏠
Working from home

Highlights

  • Pro

Organizations

@s1community @lolc2 @BADGUIDS @sinkholed

Block or report mthcht

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 250 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Red team tool for abusing Commvault to achieve lateral movement, persistence, and file collection.

C# 6 Updated Sep 9, 2025

This project aims to be a drop-in replacement for the certstream server by Calidog. This tool aggregates, parses, and streams certificate data from multiple certificate transparency logs via websoc…

Go 159 26 Updated Oct 7, 2025

A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

PowerShell 604 66 Updated Sep 25, 2025

VECTR is a tool that facilitates tracking of your red and blue team testing activities to measure detection and prevention capabilities across different attack scenarios

1,516 178 Updated Oct 1, 2025

Public repository of Sigma and YARA rules created by Synacktiv

YARA 13 1 Updated May 12, 2025

Sublime rules for email attack detection, prevention, and threat hunting.

YAML 328 79 Updated Oct 9, 2025

Public static website for the D3FEND project. For the D3FEND ontology repo see: https://github.com/d3fend/d3fend-ontology

HTML 86 16 Updated Aug 2, 2025

Stakeholder-Specific Vulnerability Categorization

Python 164 41 Updated Oct 8, 2025

A knowledge base of actionable Incident Response techniques

Python 650 122 Updated May 31, 2022

TheHive: a Scalable, Open Source and Free Security Incident Response Platform

Scala 3,828 672 Updated Jul 25, 2025

MCP Server for Ghidra

Java 6,210 469 Updated Jun 23, 2025

Matkap - hunt down malicious Telegram bots

Python 780 150 Updated Aug 11, 2025

Resolving sinkholed domains

HTML 5 Updated Mar 7, 2025

Threat-hunting tool for Linux

Rust 984 70 Updated Aug 18, 2025

Small and highly portable detection tests based on MITRE's ATT&CK.

C 11,072 2,975 Updated Oct 7, 2025
C++ 32 4 Updated Feb 28, 2025

Splunk Content Control Tool

Python 119 39 Updated Oct 8, 2025

Block file creation with use of eBPF

C 5 2 Updated Feb 21, 2025

FJTA (Forensic Journal Timeline Analyzer) is a tool that analyzes Linux filesystem (ext4, XFS) journals (not systemd-journald logs), generates timelines, and detects suspicious activities.

Python 89 8 Updated Sep 30, 2025

Windows kernel and user mode emulation.

Python 1,763 263 Updated Apr 1, 2025

A tool for checking if MFA is enabled on multiple Microsoft Services

PowerShell 1,561 218 Updated Mar 4, 2025

This repository is for Indicators of Compromise (IOCs) from Zscaler ThreatLabz public reports

YARA 73 13 Updated Jul 23, 2025

A Python reference implementation for CZDS download zone file API

Python 117 44 Updated Apr 2, 2025
Python 743 109 Updated May 7, 2025

BadZure orchestrates the setup of Azure AD tenants, populating them with diverse entities while also introducing common security misconfigurations to create vulnerable tenants with multiple attack …

Python 468 29 Updated Jul 1, 2025

🕵️‍♂️ All-in-one OSINT tool for analysing any website

TypeScript 26,595 2,129 Updated Aug 3, 2025

Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques

386 76 Updated Jan 15, 2025

Records an executable's network activity into a Full Packet Capture file (.pcap) and much more.

C# 443 22 Updated Apr 6, 2025

A comprehensive list of usable Entra ID first-party clients with pre-consented Microsoft Graph scopes, in a simple YAML-file explorable with a simple HTML GUI.

HTML 129 6 Updated Mar 26, 2025

攻击流量包,辅助安全运营/分析人员,HVV蓝队工程师开展流量攻击研判工作

67 10 Updated Sep 7, 2023
Next