
GoPurple
Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

Suricata rules for network anomaly detection

Attack and defend active directory using modern post exploitation adversary tradecraft activity

Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security…

PowerShell Obfuscator

Six Degrees of Domain Admin

Set of tools to analyze Windows sandboxes for exposed attack surface.

BlackLotus UEFI Windows Bootkit

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

DEPRECATED - MozDef: Mozilla Enterprise Defense Platform

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.

Weaponizes vulnerable signed drivers to bypass EDR kernel callbacks, object callbacks, ETW TI provider, and userland hooks for LSASS memory dumping…

Run PowerShell with rundll32. Bypass software restrictions.