
Defenses-for-Tool-Integrated-LLM
Research code and experiments for defending tool-integrated LLM agents against adversarial attacks, extending Agent Security Bench with new defense…

Research code and experiments for defending tool-integrated LLM agents against adversarial attacks, extending Agent Security Bench with new defense…

Bypass llm guardrails by confusing it with fabricated tool output.

C# Reflective loader for unmanaged binaries.

Clusters and elements to attach to MISP events or attributes (like threat actors)

Open-source framework for red-teaming generative AI systems: automate attack prompts, score model responses, and audit behavior to identify security…

A font-based deception tool for red teaming, security research, and whatever else.

Tools and PoCs for Windows syscall investigation.

Stop Windows Defender programmatically

A windows token impersonation tool

A tool to find folders excluded from AV real-time scanning using a time oracle

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

A payload delivery system which embeds payloads in an executable's icon file!

Detect EDR's exceptions by inspecting processes' loaded modules

Detection rule validation

Signtool for expired certificates

Abuses Windows Filtering Platform to launch a console as NT AUTHORITY\SYSTEM or impersonate another logged-on user for privilege escalation during…

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.