
Invoke-EDRChecker
PowerShell script that enumerates running processes, loaded DLLs, services, registry, and drivers to detect the presence of AV, EDR, and logging…

PowerShell script that enumerates running processes, loaded DLLs, services, registry, and drivers to detect the presence of AV, EDR, and logging…

Modular framework for Windows UAC bypass attacks and mitigation, featuring DLL hijacking, fileless execution, and real-time monitoring to detect and…

Zeek package to detect Zerologon

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

Kratos is a high-performance Windows File System Minifilter driver designed to detect, block, and permanently immunize

POC about how to detect windows kernel debug by pool tag.

Script to implement Q-Feeds directly on NFtables or IPtables

Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ONLY.

A canary designed to minimize the impact from certain Ransomware actors

Detection-engineering reference mapping Windows, cloud, container, identity, and ICS attack classes to Sigma rules, trust-boundary models, BYOVD…

Defensive PowerShell tool for static inspection of RAR archives and detection of CVE-2025-8088 path traversal anomalies.

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

Enhance your malware detection with WAF + YARA (WAFARAY)

This PowerShell script detects indicators of compromise for CVE-2025-53770 — a critical RCE vulnerability in Microsoft SharePoint. Created by…


An Active Defense and EDR software to empower Blue Teams

Pafish is a testing tool that uses different techniques to detect virtual machines and malware analysis environments in the same way that malware…