
GoPurple
Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

SQL powered operating system instrumentation, monitoring, and analytics.

A collection of awesome security hardening guides, tools and other resources

A binary authorization and monitoring system for macOS

Tools and Techniques for Blue Team / Incident Response

A repository of sysmon configuration modules


Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

Detect Tactics, Techniques & Combat Threats


Curated collection of Microsoft Sentinel KQL queries and tutorials for hunting threats, analyzing Azure AD sign-in logs, detecting anomalies, and…

Curated collection of EDR bypass resources including PoCs, tools, workshops, presentations, and blogs for ethical hacking and red team operations.

Scan files or process memory for CobaltStrike beacons and parse their configuration

Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and…