
ICPin
An Integrity-Check Monitoring Pintool
Tools for blue team, defensive security, and threat protection.

An Integrity-Check Monitoring Pintool

Detects CVE-2020-16898: "Bad Neighbor"

A Bro package to identify connections that are bursting (lots of data and transferring quickly).

A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection

Protect your domain controllers against Zerologon (CVE-2020-1472).

A user-mode application authorization system for MacOS written in Swift

C# port of the Get-AppLockerPolicy PS cmdlet

:dart: Prevent RubberDucky (or other keystroke injection) attacks

Behave! A monitoring browser extension for pages acting as "bad boi"

A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)


"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events.…

A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon

WebLogic Honeypot is a low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware. This is…

Powerglot encodes offensive powershell scripts using polyglots . Offensive security tool useful for stego-malware, privilege escalation, lateral…

Is this IP a C2 server?

Kernel-level tool to disable Sysmon and Windows Event Logging via driver-based hook injection, enabling stealthy post-exploitation operations on…