
TransparentTorProxy
A Linux CLI utility that transparently routes all system traffic through the Tor network using nftables. It enables rapid IP rotation and easy…

A Linux CLI utility that transparently routes all system traffic through the Tor network using nftables. It enables rapid IP rotation and easy…

Curated SIEM queries and techniques for offensive discovery of Windows privilege escalation, misconfigured ACLs, services, scheduled tasks, and…

Lua library for limiting and controlling traffic in OpenResty/ngx_lua

Iterative agent harness that uses LLMs and Certora Prover to generate and refine smart-contract CVL specs, feeding verifier output back until success…

A quick and dirty HTTP/S "organic" traffic generator.

Central console for Douglas-042 HEADQUARTERS collectors. Sweeps a fleet, correlates results across hosts, and manages IOC feeds and SIEM delivery…

Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

Customer Assurance Operating System. Answer the security questionnaires your customers send you, once.

Mitigate log4shell (CVE-2021-44228) vulnerability attacks using Nginx LUA script

Disables ImageIO TIFF support to protect against CVE-2016-4631

Go library for safe YAML and shell generation, using syntax-aware templates to detect and block injection attacks via annotations for trusted data.

Sigma rules for detecting Lazarus Group TTPs, covering malicious document execution, PowerShell abuse, scheduled tasks, and credential access,…

A personal Windows SOC suite built in PowerShell — monitors network connections, resource usage, scheduled tasks and power events with severity…

Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Automatically generated Sysmon parser for Azure Sentinel