
EtwSessionHijacking
A Poc on blocking Procmon from monitoring network events

A Poc on blocking Procmon from monitoring network events

Application-scoped Windows network brownouts in native C and BOF form

An information security preparedness tool to do adversarial simulation.

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Data from a BRAWL Automated Adversary Emulation Exercise

Adversary Emulation Framework

Automated Adversary Emulation Platform

Never ever ever use pixelation as a redaction technique

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Infection Monkey - An open-source adversary emulation platform

This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2…


Privaxy is the next generation tracker and advertisement blocker. It blocks ads and trackers by MITMing HTTP(s) traffic. Also check out my new…

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Purple Team Exercise Framework

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

PoCs and tools for investigation of Windows process execution techniques

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…