
Sentinel-Queries
Curated collection of Microsoft Sentinel KQL queries and tutorials for hunting threats, analyzing Azure AD sign-in logs, detecting anomalies, and…
Tools for blue team, defensive security, and threat protection.

Curated collection of Microsoft Sentinel KQL queries and tutorials for hunting threats, analyzing Azure AD sign-in logs, detecting anomalies, and…

Automated IP ban service that detects failed login attempts from event logs and files, blocking attackers on Windows and Linux via firewall…

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…


Weaponizes vulnerable signed drivers to bypass EDR kernel callbacks, object callbacks, ETW TI provider, and userland hooks for LSASS memory dumping…

This repo contains some Amsi Bypass methods i found on different Blog Posts.

💚🇺🇸🗽Secure remote browsing anywhere, any way you like it.

A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.

AV/EDR evasion via direct system calls.

Protect against malicious code installed via npm, yarn, pnpm, npx, pnpx, pip, uv and poetry with Aikido Safe Chain. Free to use, no tokens required.

GitHub App to set and enforce security policies

A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.

A toolset to make a system look as if it was the victim of an APT attack

attempting to detect smart glasses nearby and warn you

Hardentools simply reduces the attack surface on Microsoft Windows computers by disabling low-hanging fruit risky features.

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.

Set of tools to analyze Windows sandboxes for exposed attack surface.