
ESCepcion
Passive AD CS auditor detecting ESC1–ESC16 and Shadow Credentials via read-only LDAP/ACL/registry checks, with prioritized remediation and SIEM-ready…

Passive AD CS auditor detecting ESC1–ESC16 and Shadow Credentials via read-only LDAP/ACL/registry checks, with prioritized remediation and SIEM-ready…

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

Detection-aware BloodHound attack-path scoring - find the quietest route to your objective, calibrated across audit/EDR/SIEM tiers.

Suricata rules for network anomaly detection

Behavior-first WordPress CVE-2026-64638 scanner using benign login probes; classifies sanitizer behavior and generates alert-only PoCs for authorized…

Proof of concept MacOS post exploitation tool written in Swift. Designed as a POC for blue teams to build macOS detections. Author: Cedric Owens

Tools that trigger False Positive AV alerts

Retrieve AD accounts description and search for password in it

AutoPoC Generator HoneyPoC

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

Python alternative to Mimikatz lsadump::dcshadow

Detection rules and analysis for Dirty Frag (CVE-2026-43284/CVE-2026-43500) Linux kernel LPE vulnerability. Based on community research and health…

SUIDGuard - a TrustedBSD Kernel Extension that adds mitigations to protect SUID/SGID processes a bit more

NCC Group Ransomware Simulator

A collection of tools to enumerate and analyse Windows DACLs

Zeek package to detect Zerologon

A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

Detect Linux rootkits which use signals to elevate process privileges.