
AzureAD-Attack-Defense
This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…
Tools for blue team, defensive security, and threat protection.

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

Rapidly Search and Hunt through Windows Forensic Artefacts

Local-first encrypted password vault for Android with Master Password access, Recovery Key support, Autofill integration, and portable encrypted…

ML-based detection of Zombie ZIP archive header evasion attacks (CVE-2026-0866)

MDE relies on some of the Audit settings to be enabled

Highly advanced Linux anti-exploitation and anti-tamper binary protector for ELF.

HardeningKitty - Checks and hardens your Windows configuration

Go library for safe YAML and shell generation, using syntax-aware templates to detect and block injection attacks via annotations for trusted data.

Just a git repo for the sleepmask detection rule i found in https://codex-7.gitbook.io/codexs-terminal-window/blue-team/detecting-cobalt-strike/sleep-…

Docker configuration to quickly setup your own Canarytokens.

A repository that maps commonly used attacks using MSRPC protocols to ATT&CK

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…

A repository of sysmon configuration modules

A simple binary wrapper for DNS canarytokens.

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

AutoPoC Generator HoneyPoC

Detect Tactics, Techniques & Combat Threats