
AV-EDR-Lab-Environment-Setup
AV/EDR Lab environment setup references to help in Malware development

AV/EDR Lab environment setup references to help in Malware development

Rules generated from our investigations.

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Assist reverse tcp shells in post-exploration tasks

Sigma rules from Joe Security

Use dropbear over wireguard.

Sigma rules to share with the community

Bypass age verification service from redhat

一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.

BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR

Protect your parents from phishing

Create Basic SSH Honeypot With Python

Slides from various conference talks

详细讲解CitrixBleed 2 — CVE-2025-5777(越界泄漏)PoC 和检测套件


A repository to release detection rules to the public

Detection of Linux Malware C2 RedXOR - demonstration

Blocking the DirtyFrag Linux LPE chain (CVE-2026-43284 / CVE-2026-43500) at runtime with a Cilium Tetragon TracingPolicy