
ThreatSentry-AI
ThreatSentry AI is an intelligent threat hunting dashboard that leverages machine learning to proactively identify and prioritize risks in your…

ThreatSentry AI is an intelligent threat hunting dashboard that leverages machine learning to proactively identify and prioritize risks in your…

Kernel-mode Windows driver for real-time detection of process injection techniques, including shellcode, DLL, and reflective injection, with syscall…

A tool for simplifying the process of researching IOCs.

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Enumerate various traits from Windows processes as an aid to threat hunting

The NoSQL Honeypot Framework

Detection rule validation

Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the intentions of…

Windows tool to list, get, set, protect, and unprotect process protection levels (PP/L) for debugging, inspection, and privilege escalation.

Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.

An interactive shell to spoof some LOLBins command line

Robust Subdomain Takeover Tool

Red Team C code repo

Protect process by shellcode

Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build…

PowerShell script that enumerates running processes, loaded DLLs, services, registry, and drivers to detect the presence of AV, EDR, and logging…

Open-source Windows kernel-level EDR lab for understanding and testing detection methods against process injection, credential dumping, and other…

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…