
RemotePSpy
Live monitoring tool for remote PowerShell sessions using ETW to capture and decode WinRM/PSRP protocol, providing command execution traces and…

Live monitoring tool for remote PowerShell sessions using ETW to capture and decode WinRM/PSRP protocol, providing command execution traces and…

Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome…

Passive vulnerability scanner for CVE-2026-1731 — BeyondTrust RS/PRA pre-auth RCE (CVSS 9.9). Educational & defensive use only.

Rust tool to detect cell site simulators on an orbic mobile hotspot

Python tool for safe archive handling, path traversal awareness, and secure extraction. Inspired by CVE-2025-8088.

Official guidance and workarounds for CVE-2022-30190, a remote code execution vulnerability in the Microsoft Support Diagnostic Tool (MSDT)…

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

A lightweight tool designed to stop clickfix attacks by using clipboard formatting with execution surface checks

"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events.…

Security Tool to detect arp poisoning attacks

An information security preparedness tool to do adversarial simulation.

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Simulates attacker actions in Okta environments to test monitoring and detection capabilities, with modules mapped to MITRE ATT&CK tactics for red…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

BlueHound - pinpoint the security issues that actually matter

Open-source URL masking & analysis tool for security research, phishing awareness, and defensive testing. Demonstrates adversary techniques used to…

Safe ransomware simulation tool for testing antivirus detection. Simulates macro staging, volume shadow copy deletion, document encryption, and note…

A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.