
sandbox-attacksurface-analysis-tools
Set of tools to analyze Windows sandboxes for exposed attack surface.

Set of tools to analyze Windows sandboxes for exposed attack surface.

👁🗨 This script will simulate fake processes of analysis sandbox/VM software that some malware will try to avoid.

Hide your Powershell script in plain sight. Bypass all Powershell security features

This PowerShell script detects indicators of compromise for CVE-2025-53770 — a critical RCE vulnerability in Microsoft SharePoint. Created by…

C# port of the Get-AppLockerPolicy PS cmdlet

Powershell to mitigate CVE-2022-29072

The Azure Active Directory Incident Response PowerShell module provides a number of tools, developed by the Azure Active Directory Product Group in…

SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated…

Defensive PowerShell tool for static inspection of RAR archives and detection of CVE-2025-8088 path traversal anomalies.

PowerShell Script for initial mitigation of vulnerability

A PowerShell script that automates the security assessment of Microsoft 365 environments.

Powerglot encodes offensive powershell scripts using polyglots . Offensive security tool useful for stego-malware, privilege escalation, lateral…

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

PowerShell script that enumerates running processes, loaded DLLs, services, registry, and drivers to detect the presence of AV, EDR, and logging…

A PowerShell script to temporarily mitigate the CVE-2024-38063 vulnerability by disabling IPv6 on Windows systems. This workaround modifies the…

PowerShell tool for red teamers that clears execution evidence by stopping event logging, removing file and registry artifacts, and saving timestamps…

Automation to assess the state of your M365 tenant against CISA's baselines

Rail-OT-Protector (ROP) — free, open-source cybersecurity scanning tool for rail and transit OT/SCADA networks. PowerShell + Bash scanners for…