
PersistenceSniper
Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

Snort 3 IDS → IPS lab on Kali. Custom detection rules + iptables enforcement against ICMP recon, Nmap SYN scans, Hydra FTP brute force, and vsftpd…

A tool for creating hidden accounts using the registry || 一个使用注册表创建隐藏帐户的工具

Python alternative to Mimikatz lsadump::dcshadow

Powershell Empire Persistence finder


Active deception tool that transparently migrates attackers from real targets to honeypots during exploitation and post-exploitation, supporting…

PowerShell-based backdoor detection tool for VMware Horizon connection servers, targeting CVE-2021-44228. Includes canary with optional submission…

EDRUnChoker - fileless WMI defense that removes EDRChoker QoS throttling policies

Detection of Linux Malware C2 RedXOR - demonstration

An ssh honeypot with the XZ backdoor. CVE-2024-3094