
GadgetToJScript
A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

A productionized greedy coordinate gradient (GCG) attack tool for large language models (LLMs)

A font-based deception tool for red teaming, security research, and whatever else.

The Python Risk Identification Tool for generative AI (PyRIT) is an open source framework built to empower security professionals and engineers to…

image scaling attacks for multi-modal prompt injection

Playing around with Stratus Red Team (Cloud Attack simulation tool) and SumoLogic

Generate Linux executables that simulate adversary behaviors and techniques for testing detection and response coverage. Consumes JSON for easy…

Abuses Windows Filtering Platform to launch a console as NT AUTHORITY\SYSTEM or impersonate another logged-on user for privilege escalation during…

Open-source framework for red-teaming generative AI systems: automate attack prompts, score model responses, and audit behavior to identify security…

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

A payload delivery system which embeds payloads in an executable's icon file!

CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.

Detect EDR's exceptions by inspecting processes' loaded modules

A tool to find folders excluded from AV real-time scanning using a time oracle


Research code and experiments for defending tool-integrated LLM agents against adversarial attacks, extending Agent Security Bench with new defense…

Clusters and elements to attach to MISP events or attributes (like threat actors)