
AzureAD-Attack-Defense
This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

POC about how to detect windows kernel debug by pool tag.

This repository documents how deployment of Microsoft Defender for Endpoint on a Windows 11 device, including onboarding via local script, enabling…

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

Database firewall written in Go

Research project reverse-engineering Windows Security Center COM interfaces to trace AV registration through ATL, vtable, WSCAPI, and RPC, with…

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

Accompanying PowerShell Modules for DevSec Defense Presentation

Proof-of-concept tool for detecting AMSI (Antimalware Scan Interface) bypasses and malicious in-memory script activity on Windows endpoints.

Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool

Chronicle parser for CORELIGHT and related information.

Vulnerability Analysis of CVE-2026-83548 affecting SonicWall SMA1000 security systems.

Detection of Linux Malware C2 RedXOR - demonstration

Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks

Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).