Skip to content
View hardsoftsecurity's full-sized avatar

Block or report hardsoftsecurity

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

An advanced memory forensics framework

Python 7,917 1,343 Updated May 16, 2025

Small and highly portable detection tests based on MITRE's ATT&CK.

C 11,395 3,033 Updated Dec 18, 2025

Practical Windows Forensics Training

PowerShell 703 139 Updated Feb 29, 2024

Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.

Nim 245 29 Updated Dec 18, 2025

Execute commands interactively on remote Windows machines using the WinRM protocol

Python 302 27 Updated Dec 20, 2025

Tool for issuing manual LDAP queries which offers bofhound compatible output

Python 36 5 Updated Dec 11, 2025

Fileless lateral movement tool that relies on ChangeServiceConfigA to run command

C 1,571 257 Updated Jul 10, 2023

Generate BloodHound compatible JSON from logs written by ldapsearch BOF, pyldapsearch and Brute Ratel's LDAP Sentinel

Python 336 30 Updated Dec 16, 2025

Situational Awareness commands implemented using Beacon Object Files

C 1,651 271 Updated Nov 24, 2025

Reparent a running program to a new terminal

C 6,133 227 Updated Nov 20, 2025

SSH man-in-the-middle tool

C 1,729 211 Updated Jul 2, 2021

A small utility to translate NTDS.dit files to SQLite format.

Python 79 8 Updated Oct 11, 2023

This aims to be a collection of tools to forensically analyze Active Directory databases

Rust 25 3 Updated Jun 11, 2025

Active Directory forensic framework

Python 327 104 Updated Mar 24, 2022

Credentials Dumper for Linux using eBPF

C 1,156 65 Updated Sep 9, 2024

A collection of Awesome Google Dorks.

596 84 Updated Jul 1, 2024

A set of Zeek scripts to detect ATT&CK techniques.

Zeek 620 83 Updated Jun 26, 2024

LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, such as those powered by Android. The tool supports acquir…

C 1,908 361 Updated Nov 9, 2025

binwalk for Windows

Python 58 37 Updated Nov 19, 2022

Sysmon for Linux

C 2,042 209 Updated Jul 3, 2025

A secure sandbox environment for malware developers and red teamers to test payloads against detection mechanisms before deployment. Integrates with LLM agents via MCP for enhanced analysis capabil…

YARA 1,244 141 Updated Nov 12, 2025

Volatility 3.0 development

Python 3,771 608 Updated Dec 16, 2025

OpenPLC Editor - IDE capable of creating programs for the OpenPLC Runtime

Shell 541 245 Updated Nov 6, 2025

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

Go 13,376 1,738 Updated Nov 27, 2025

Printer Exploitation Toolkit - The tool that made dumpster diving obsolete.

Python 4,192 643 Updated Aug 2, 2024