
Seatbelt
C# host-survey tool for offensive and defensive security, performing extensive safety checks on Windows systems including user, system, and network…

C# host-survey tool for offensive and defensive security, performing extensive safety checks on Windows systems including user, system, and network…

Graph-based tool for mapping and analyzing identity and privilege relationships across Active Directory, Azure, and other identity platforms to…

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Retrieve AD accounts description and search for password in it

DNS traffic sniffer and analyzer for monitoring, filtering, and detecting anomalies in DNS queries. Features include PCAP export, DoH support, and a…

Multi-protocol honeypot simulator supporting 50+ network services with deep interaction, TCP/UDP/ICMP logging, JA3 fingerprinting, and virtual…

Slack enumeration and exposed secrets detection tool

C# tool that enumerates running processes, loaded DLLs, installed services, and drivers to detect the presence of AV, EDR, and logging products,…

CLI tool to confirm if an IP:port hosts an Empire C2 server, with support for masscan output parsing and batch scanning from file or stdin.

A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

Low-observability Active Directory security enumeration tool using native ADSI/COM interfaces. Enumerates ACLs, delegation, trusts, ADCS, Kerberoast…

Tool to identify custom or undocumented folder exclusions in AV/EDR by detecting userland hook count differences, enabling red teams to find blind…

Real-time vulnerability intelligence platform aggregating CVE, exploits, and threat news for SOC and threat hunting teams.

Zeek plugin for detecting and parsing OpenVPN traffic (UDP/TCP with TLS), extracting session and TLS handshake metadata for network security…

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

WordPress honeypot that detects probes for plugins, themes, and common fingerprinting files. Configurable via CLI or config file, with theme and…

PowerShell script that enumerates running processes, loaded DLLs, services, registry, and drivers to detect the presence of AV, EDR, and logging…

Lightweight Python-based SSH honeypot that simulates a vulnerable SSH server to log attacker commands, credentials, and connection attempts for…