
EventLogging
Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.
Tools for blue team, defensive security, and threat protection.

Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.

The Azure Active Directory Incident Response PowerShell module provides a number of tools, developed by the Azure Active Directory Product Group in…

CA Optics - Azure AD Conditional Access Gap Analyzer

Audit program for AzureAD

A wrapper of voku/anti-xss for Laravel


Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.


These are the source codes of the Python scripts to apply the temporary protection against the CVE-2022-30190 vulnerability (Follina)

Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks

Removes the ability for MSDT to run, in response to CVE-2022-30190 (Follina)

A ModSecurity ruleset for detecting potential attacks using CVE-2018-6389

Discord bot for mitigating the aCropalypse vulnerability (CVE-2023-21036, CVE-2023-28303) by retroactively deleting vulnerable images

Simple honeypot for CVE-2021-41773 vulnerability

A vulnerable driver exploited by me (BYOVD) that is capable of terminating several EDRs and antivirus software in the market, rendering them…

MSDT protocol disabler (CVE-2022-30190 patch tool)
