
ring3-kit
Hides Process From Task Manager Using NT API Hooking (NtQuerySystemInformation)

Hides Process From Task Manager Using NT API Hooking (NtQuerySystemInformation)

Active deception tool that transparently migrates attackers from real targets to honeypots during exploitation and post-exploitation, supporting…

.NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on disk binaries.

BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR

The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from…

Protect your parents from phishing

PISIGuard runs entirely in your browser. It spots names, email addresses, phone numbers, credit card numbers, passwords, API keys, and more, replaces…

DDWPasteRecon tool will help you identify code leak, sensitive files, plaintext passwords, password hashes. It also allow member of SOC & Blue Team…

Slides from various conference talks

Automates migration of AWS workloads from IMDSv1 to IMDSv2 to mitigate SSRF attacks. Detects IMDSv1 usage across EC2, ECS, EKS, Lightsail, and more,…

Kernel-level security engine using eBPF-LSM to enforce file access policies based on process lineage, protecting sensitive data from supply-chain…

Automated YARA rule generation from the Cert Central compromised certificate database.

Dynamically generated Suricata rules from real-time threat feeds

This is a "insmod" blocking tool module for Linux Kernel, protecting the user from the loading of malicious code in Linux Kernel - rootkits, for…

Breaking down CVE-2025-54253 — an Adobe AEM-Forms exploit path from XXE to full remote code execution and its real-world impact.

Strip credential-like content from free-form strings before they reach logs or telemetry. Part of the phpboyscout Go toolkit. ·…

A lightweight eBPF program to monitor file creation and modification events on Linux. This tool leverages eBPF (Extended Berkeley Packet Filter) to…

An active cyber defense & honeypot system for OpenWrt routers running from a USB drive.