


bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

Software sandbox for storage of sensitive information in memory.

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

Curated collection of EDR bypass resources including PoCs, tools, workshops, presentations, and blogs for ethical hacking and red team operations.

Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the intentions of…

A PowerShell script that automates the security assessment of Microsoft 365 environments.

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Enumerate and disable common sources of telemetry used by AV/EDR.

Live hunting of code injection techniques

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

Kernel-mode Windows driver for real-time detection of process injection techniques, including shellcode, DLL, and reflective injection, with syscall…

A curated list of smart contract attack vectors

Collection of private Yara rules.