
BruteRatel-DetectionTools
A collection of Tools and Rules for decoding Brute Ratel C4 badgers

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

Tools and Techniques for Blue Team / Incident Response

Project that brings together several pentest tools

A collection of tools to enumerate and analyse Windows DACLs

A collection of awesome security hardening guides, tools and other resources

Curated collection of EDR bypass resources including PoCs, tools, workshops, presentations, and blogs for ethical hacking and red team operations.


SQL powered operating system instrumentation, monitoring, and analytics.

A repository of sysmon configuration modules

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…


Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and…

honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS…

Live hunting of code injection techniques

Collection of private Yara rules.