
AtomicSyscall
Tools and PoCs for Windows syscall investigation.

Tools and PoCs for Windows syscall investigation.

Windows token impersonation tool to list tokens, execute commands as impersonated users, and add domain admin users during Active Directory pentests.

An information security preparedness tool to do adversarial simulation.

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

C# adversary simulation tool executing 47+ MITRE ATT&CK techniques in Windows Active Directory environments to generate attack telemetry for…

This is the tool to dump the LSASS process on modern Windows 11

A font-based deception tool for red teaming, security research, and whatever else.

Proof-of-concept tool for generating adversarial perturbations to exploit weaknesses in deep learning models, based on DEF CON 25 presentation.

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

Playing around with Stratus Red Team (Cloud Attack simulation tool) and SumoLogic

Adversary emulation tool for Windows that executes MITRE ATT&CK techniques via PowerShell to simulate real threats, test defenses, and validate…

A tool to find folders excluded from AV real-time scanning using a time oracle

A productionized greedy coordinate gradient (GCG) attack tool for large language models (LLMs)

Security benchmark for evaluating OpenClaw agents against adversarial execution contexts including poisoned files, injected skills, misleading tool…

Proof-of-concept demonstrating cross-channel trust fragmentation attacks on MCP-based AI coding assistants, splitting malicious instructions across…

Evaluation framework that tests whether large language models follow invisible Unicode-encoded instructions embedded in normal-looking text, with…

Python3 tool for DNS spoofing attacks. Sniffs network, intercepts DNS queries, and sends forged responses to redirect victims to a specified IP.