
HASH
YAML-configurable low-interactive honeypot framework for deploying HTTP/HTTPS-based deception servers with built-in honeytraps and Datadog log…
Tools for blue team, defensive security, and threat protection.

YAML-configurable low-interactive honeypot framework for deploying HTTP/HTTPS-based deception servers with built-in honeytraps and Datadog log…

Automates migration of AWS workloads from IMDSv1 to IMDSv2 to mitigate SSRF attacks. Detects IMDSv1 usage across EC2, ECS, EKS, Lightsail, and more,…

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

Centralized IoC scanner that deploys Loki across endpoints, collects detection results, and parses logs into CSV for incident response and forensic…

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

.NET, PE, & Raw Shellcode Packer/Loader Written in Nim

Lightweight utility to fool port scanners

Rogue Assembly Hunter is a utility for discovering 'interesting' .NET CLR modules in running processes.

A tool for creating hidden accounts using the registry || 一个使用注册表创建隐藏帐户的工具

Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and…

A Developer and Security Engineer friendly package for Securing NodeJS Applications.

A Software as a Service (SaaS) log collection framework.

A PowerShell script that automates the security assessment of Microsoft 365 environments.

Weaponizes vulnerable signed drivers to bypass EDR kernel callbacks, object callbacks, ETW TI provider, and userland hooks for LSASS memory dumping…

DDWPasteRecon tool will help you identify code leak, sensitive files, plaintext passwords, password hashes. It also allow member of SOC & Blue Team…

Web interface for Suricata ruleset management, threat hunting, and rule tuning with multi-source feed aggregation, transformation, and activity…

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

A unique technique to execute binaries from a password protected zip