#1Tools for blue team, defensive security, and threat protection.
Kitploit recommended

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

DEPRECATED - MozDef: Mozilla Enterprise Defense Platform

Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs

Spartacus DLL/COM Hijacking Toolkit

Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ONLY.

C# wrapper for ETW that serializes kernel and user-mode event data to JSON for threat hunting, malware analysis, and incident response, with Yara…


A MITM (monster-in-the-middle) detection tool. Used to build MALCOLM:

Shellcode injection technique. Given as C++ header, standalone Rust program or library.

Building an Active Directory domain and hacking it

Detection signature repository providing YARA rules and threat-hunting content for identifying malware and malicious activity across enterprise…

RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, it first…

Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.

A low to medium interaction honeypot.

The Azure Active Directory Incident Response PowerShell module provides a number of tools, developed by the Azure Active Directory Product Group in…

An Open-Source Pre and Post Callback-Based Framework for macOS Kernel Monitoring.