
PPLcontrol
Windows tool to list, get, set, protect, and unprotect process protection levels (PP/L) for debugging, inspection, and privilege escalation.

Windows tool to list, get, set, protect, and unprotect process protection levels (PP/L) for debugging, inspection, and privilege escalation.

GRC platform for risk management, compliance, and audit with 200+ frameworks, automatic control mapping, vulnerability management, and incident…

Detect Tactics, Techniques & Combat Threats

Crescendo is a swift based, real time event viewer for macOS. It utilizes Apple's Endpoint Security Framework.

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Automated IP ban service that detects failed login attempts from event logs and files, blocking attackers on Windows and Linux via firewall…

Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks

Security sensor for realtime threat detection and protection

Automated System Hardening Framework

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

C# port of the Get-AppLockerPolicy PS cmdlet

Scans exported Azure domain dumps for plaintext passwords, connection strings, storage keys, and other secrets; generates redacted CSV/HTML reports…

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

This repository documents how deployment of Microsoft Defender for Endpoint on a Windows 11 device, including onboarding via local script, enabling…