
Voidgate
A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

Generate Linux executables that simulate adversary behaviors and techniques for testing detection and response coverage. Consumes JSON for easy…

Malware Mutation Using Reinforcement Learning and Generative Adversarial Networks

Practical black-box adversarial packet generation against encrypted traffic classification with minimal overhead and full packet recoverability.

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…


Purple Team Exercise Framework

Attempt at Obfuscated version of SharpCollection

Data from a BRAWL Automated Adversary Emulation Exercise

A high-severity prompt injection flaw in Claude AI proves that even the smartest language models can be turned into weapons — all with a few lines of…

Reverse Shell Detection with Machine Learning

A DNS spoofer tool written in Python3.

Never ever ever use pixelation as a redaction technique

PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows…

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

A windows token impersonation tool