
misp-galaxy
Clusters and elements to attach to MISP events or attributes (like threat actors)

Clusters and elements to attach to MISP events or attributes (like threat actors)

A PoC ransomware sample to test out your ransomware response strategy.

A diagnostic framework for measuring LLM vulnerability to Affective Contextual Erosion (ACE) and related liminal attack vectors. **Delirium** is not…

Security benchmark for evaluating OpenClaw agents against adversarial execution contexts including poisoned files, injected skills, misleading tool…

PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows…

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

Tools and PoCs for Windows syscall investigation.

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…


Generate Linux executables that simulate adversary behaviors and techniques for testing detection and response coverage. Consumes JSON for easy…

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Detect EDR's exceptions by inspecting processes' loaded modules

A tool to find folders excluded from AV real-time scanning using a time oracle

Detection rule validation

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Signtool for expired certificates

Playing around with Stratus Red Team (Cloud Attack simulation tool) and SumoLogic