
BloodHound
Six Degrees of Domain Admin
Tools for blue team, defensive security, and threat protection.

Six Degrees of Domain Admin

eBPF-based runtime kernel security monitor detecting exploits and rootkits via control flow integrity (wCFI) and privilege escalation detection (PSD)…

Timestomp Tool to flatten MAC times with a specific timestamp

Open-source URL masking & analysis tool for security research, phishing awareness, and defensive testing. Demonstrates adversary techniques used to…

Scan strings or files for malware using the Windows Antimalware Scan Interface

DNS traffic sniffer and analyzer for monitoring, filtering, and detecting anomalies in DNS queries. Features include PCAP export, DoH support, and a…

PowerShell-based security toolkit for small-to-medium enterprises, providing automated alerts, Active Directory hardening, Windows Event Forwarding,…

Azure-based client inventory and drift detection tool that collects Windows configuration data (antivirus, patching, Bitlocker) into LogAnalytics for…

A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to evade…

PowerShell script that enumerates running processes, loaded DLLs, services, registry, and drivers to detect the presence of AV, EDR, and logging…

Safe ransomware simulation tool for testing antivirus detection. Simulates macro staging, volume shadow copy deletion, document encryption, and note…


Anti Forensics Tool For Red Teamers, Used For Erasing Footprints In The Post Exploitation Phase.

🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

Windows tool to list, get, set, protect, and unprotect process protection levels (PP/L) for debugging, inspection, and privilege escalation.

PowerShell script that automatically tests CMD bypass methods on Windows, evaluates results, calculates a security score, and provides hardening…

A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.

Open-source Windows kernel-level EDR lab for understanding and testing detection methods against process injection, credential dumping, and other…