Lists (2)
Sort Name ascending (A-Z)
Stars
Unlocking _everything_ on the CPU with DRAM scrambling
Deep insights into EDR detection approaches
Project for generating and identifying deceptive LNK files.
Project for tracking publicly disclosed DLL Hijacking opportunities.
AI-powered red team agent that generates attack scenarios, attack chains, and defense playbooks from system architecture descriptions
Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build of Windows | Provides tools and Guides for Pers…
A modern platform for visual, flexible, and extensible graph-based investigations. For cybersecurity analysts and investigators.
Custom EDR for testing some malware evasion techniques.
Bicep is a declarative language for describing and deploying Azure resources
Threat Model Knowledge Base - Security context source for AI-assisted development
This project aims to compare and evaluate the telemetry of various EDR products.
A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA based scripts.
Native API online documentation, based on the System Informer (formerly Process Hacker) phnt headers
Moonwalk++: Simple POC Combining StackMoonwalking and Memory Encryption
Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode
Windows protocol library, including SMB and RPC implementations, among others.
A collection of Azure AD/Entra tools for offensive and defensive security purposes
Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.
An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents
PoC Implementation of a fully dynamic call stack spoofer
Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).
Portable Executable reversing tool with a friendly GUI
Gather and update all available and newest CVEs with their PoC.