
Tools for blue team, defensive security, and threat protection.


Apply a filter to the events being reported by windows event logging

AntiSpy is a free but powerful anti virus and rootkits toolkit.It offers you the ability with the highest privileges that can detect,analyze and…

Qubes containerization on Windows

PoC memory injection detection agent based on ETW, for offensive and defensive research purposes

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions


Run PowerShell with rundll32. Bypass software restrictions.

A Canary which fires when uninstalled

Enumerate and disable common sources of telemetry used by AV/EDR.

A canary designed to minimize the impact from certain Ransomware actors

Obfuscate specific windows apis with different apis

CommunityHoneyNetwork Server

Host IDS for desktop users

MITRE ATT&CK mapped queries for SentinelOne Deep Visiblity

Proof of concept MacOS post exploitation tool written in Swift. Designed as a POC for blue teams to build macOS detections. Author: Cedric Owens

DropEngine provides a malleable framework for creating shellcode runners, allowing operators to choose from a selection of components and combine…

Draw.io libraries for threat modeling diagrams