
EDRUnChoker
EDRUnChoker - fileless WMI defense that removes EDRChoker QoS throttling policies

EDRUnChoker - fileless WMI defense that removes EDRChoker QoS throttling policies

Snort 3 IDS → IPS lab on Kali. Custom detection rules + iptables enforcement against ICMP recon, Nmap SYN scans, Hydra FTP brute force, and vsftpd…

Active deception tool that transparently migrates attackers from real targets to honeypots during exploitation and post-exploitation, supporting…

Python alternative to Mimikatz lsadump::dcshadow

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

An ssh honeypot with the XZ backdoor. CVE-2024-3094

A tool for creating hidden accounts using the registry || 一个使用注册表创建隐藏帐户的工具

PowerShell-based backdoor detection tool for VMware Horizon connection servers, targeting CVE-2021-44228. Includes canary with optional submission…


Detection of Linux Malware C2 RedXOR - demonstration

Powershell Empire Persistence finder