
dcshadow
Python alternative to Mimikatz lsadump::dcshadow

Python alternative to Mimikatz lsadump::dcshadow

Powershell Empire Persistence finder

An ssh honeypot with the XZ backdoor. CVE-2024-3094

Active deception tool that transparently migrates attackers from real targets to honeypots during exploitation and post-exploitation, supporting…

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

A tool for creating hidden accounts using the registry || 一个使用注册表创建隐藏帐户的工具

EDRUnChoker - fileless WMI defense that removes EDRChoker QoS throttling policies

Windows tool that disables Driver Signature Enforcement by patching kernel variables, allowing unsigned drivers to load for testing and research.

choose and hide windows files/path from kernel space using this driver


PowerShell-based backdoor detection tool for VMware Horizon connection servers, targeting CVE-2021-44228. Includes canary with optional submission…

Black-box input-stage purification defense that neutralizes backdoor attacks on object detectors via corruption, diffusion reconstruction, and DBSCAN…

Snort 3 IDS → IPS lab on Kali. Custom detection rules + iptables enforcement against ICMP recon, Nmap SYN scans, Hydra FTP brute force, and vsftpd…

Detection of Linux Malware C2 RedXOR - demonstration