
NorkNork
Powershell Empire Persistence finder

Powershell Empire Persistence finder

SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated…

PowerShell script that automatically tests CMD bypass methods on Windows, evaluates results, calculates a security score, and provides hardening…

POC Highlighting Obfuscation Techniques used by FIN threat actors based on cmd.exe's replace functionality and cmd.exe/powershell.exe's stdin command…

PowerShell script that applies a temporary registry-based mitigation for CVE-2026-21509, a Microsoft Office security feature bypass, with backup and…

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

A personal Windows SOC suite built in PowerShell — monitors network connections, resource usage, scheduled tasks and power events with severity…

High fidelity defensive security lab simulating a DoD aligned enterprise network with Active Directory, VLAN segmentation, STIG based hardening,…

quick powershell script to fix cve-2024-38063

Run Powershell without software restrictions.

Accompanying PowerShell Modules for DevSec Defense Presentation

Powershell to mitigate CVE-2022-29072

Powershell script with Detection and Remediation for CVE-2026-21509

A small powershell script to disable print spooler service using desired state configuration

PowerShell script to mitigate CVE-2022-30190 by updating a registry DWORD key, designed for deployment via RMM tools like ConnectWise Automate.

PowerShell Script for initial mitigation of vulnerability

This powershell script is intended to be used by anyone looking to remediate the Log4j Vulnerability within their environment. It can target multiple…

A PowerShell script to temporarily mitigate the CVE-2024-38063 vulnerability by disabling IPv6 on Windows systems. This workaround modifies the…