


Open-source framework for red-teaming generative AI systems: automate attack prompts, score model responses, and audit behavior to identify security…

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

An information security preparedness tool to do adversarial simulation.

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

image scaling attacks for multi-modal prompt injection

Disables Windows Defender by creating a token with TrustedInstaller and Windefend service accounts; designed for one-click use in post-exploitation…

PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows…

Obfuscates C# executables with AV-evasion techniques to bypass Windows Defender; simple drag-and-drop CLI for generating red-team payloads.

Clusters and elements to attach to MISP events or attributes (like threat actors)

This is the tool to dump the LSASS process on modern Windows 11

Patches Microsoft's signtool to sign with expired certificates via an XmlLite.dll shim; also explains mitigation through the Windows vulnerable…

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

C# Reflective loader for unmanaged binaries.

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

Tools and PoCs for Windows syscall investigation.

Generate Linux executables that simulate adversary behaviors and techniques for testing detection and response coverage. Consumes JSON for easy…

Windows token impersonation tool to list tokens, execute commands as impersonated users, and add domain admin users during Active Directory pentests.