
internal-security-detect
The detection of internal security controls at a company

The detection of internal security controls at a company

Hardentools simply reduces the attack surface on Microsoft Windows computers by disabling low-hanging fruit risky features.

Automated System Hardening Framework

Web-based tool for managing and deploying Sysmon configurations across Windows endpoints via agentless (WMI/SMB) or agent-based methods, with remote…

CY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271

Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Default Detections for EDR

XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template

Nix Audit made easier (RHEL, CentOS)

Azure AD Password Checker

Helps defenders find their WSUS configurations in the wake of CVE-2025-59287

Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool

The remediation script should set the reg entries described in https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884 . The detection…

Technical analysis, root cause breakdown, and non-destructive detection methodology for CVE-2026-63030.

Shell script that detects vulnerable Open vSwitch kernel modules, blocks automatic loading, removes the affected module, and verifies mitigation…

Controlled NGINX HTTP/2 frame injection lab for CVE-2026-42926 patch validation and defensive research

Script para comprobar si la vulnerabilidad de Linux CIFSwitch (CVE-2026-46243) nos afecta. Detecta configuraciones potencialmente vulnerables y…