Lists (7)
Sort Name ascending (A-Z)
Starred repositories
GoodbyeDPI — Deep Packet Inspection circumvention utility (for Windows)
Small and highly portable detection tests based on MITRE's ATT&CK.
Simple tool to configure Windows Filtering Platform (WFP) which can configure network activity on your computer.
clumsy makes your network condition on Windows significantly worse, but in a controlled and interactive manner.
Simple (relatively) things allowing you to dig a bit deeper than usual.
eBPF implementation that runs on top of Windows
EasyHook - The reinvention of Windows API Hooking
SimpleVisor is a simple, portable, Intel VT-x hypervisor with two specific goals: using the least amount of assembly code (10 lines), and having the smallest amount of VMX-related code to support d…
LSASS memory dumper using direct system calls and API unhooking.
A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.
Native API header files for the System Informer project.
A tiny hand crafted CPU emulator, C compiler, and Operating System
Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and correlation rules by Blue teams.
Libtpms-based TPM emulator with socket, character device, and Linux CUSE interface.
Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.
This repository contains sample programs that mimick behavior found in real-world malware. The goal is to provide source code that can be compiled and used for learning purposes, without having to …
Verneuil is a VFS extension for SQLite that asynchronously replicates databases to S3-compatible blob stores.
Executes PowerShell from an unmanaged process
Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll
Transparent SSL/TLS proxy for decrypting and diverting network traffic to other programs, such as UTM services, for deep SSL inspection
High performance hybrid classical-quantum computing learning framework written in C
The first analysis framework for CPU microcode