
ransomware-simulator
Safe ransomware simulation tool for testing antivirus detection. Simulates macro staging, volume shadow copy deletion, document encryption, and note…

Safe ransomware simulation tool for testing antivirus detection. Simulates macro staging, volume shadow copy deletion, document encryption, and note…

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

A tool to recover from ESXiArgs ransomware

Windows tool to list, get, set, protect, and unprotect process protection levels (PP/L) for debugging, inspection, and privilege escalation.

Robust Subdomain Takeover Tool

Windows RPC firewall that audits, detects, and blocks malicious remote procedure calls to prevent lateral movement, reconnaissance, and exploitation…

Proof-of-concept tool leveraging WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries, enabling EDR bypass for…

A powerful and flexible tool to apply active attacks for disrupting stegomalware

Tool to identify the best mechanisms for privately disclosing a security vulnerability for a package/project.

SigCorr is the first open-source tool to detect cross-protocol attack chains spanning SS7/MAP, Diameter S6a, and GTPv2-C through unified subscriber…

A PowerShell script to temporarily mitigate the CVE-2024-38063 vulnerability by disabling IPv6 on Windows systems. This workaround modifies the…

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

This repository has both an attack detection tool and a Proof-of-Concept (PoC) Python script for the WinRAR CVE-2023-38831 vulnerability.

Simulate the behavior of AV/EDR for malware development training.

Powershell to mitigate CVE-2022-29072

Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the intentions of…

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

A lightweight tool designed to stop clickfix attacks by using clipboard formatting with execution surface checks