
CVE-2026-54121-CertiGhost
CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.

CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.

Open-source framework for red-teaming generative AI systems: automate attack prompts, score model responses, and audit behavior to identify security…

Clusters and elements to attach to MISP events or attributes (like threat actors)

image scaling attacks for multi-modal prompt injection

C# obfuscator that bypass windows defender

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Generate Linux executables that simulate adversary behaviors and techniques for testing detection and response coverage. Consumes JSON for easy…

Tools and PoCs for Windows syscall investigation.

Abuses Windows Filtering Platform to launch a console as NT AUTHORITY\SYSTEM or impersonate another logged-on user for privilege escalation during…

Malware Mutation Using Reinforcement Learning and Generative Adversarial Networks

Detect EDR's exceptions by inspecting processes' loaded modules

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

A payload delivery system which embeds payloads in an executable's icon file!

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Detection rule validation

Research code and experiments for defending tool-integrated LLM agents against adversarial attacks, extending Agent Security Bench with new defense…

Experiments for control-token chain-of-thought suppression and parser-leniency attacks on tool-using LLM agents