
RedTeamCCode
Red Team C code repo

Red Team C code repo

Dynamic Windows API resolver and unhooker that detects and restores hooked functions (IAT, EAT, inline patches) to invoke unmonitored system calls…

Windows API hooking tool that dynamically spoofs and conceals process arguments via Detours library and PEB manipulation, enabling stealthy process…

Binaries, PowerShell scripts and information about Digital Signature Hijacking.

Enumerate and disable common sources of telemetry used by AV/EDR.

CLI and Go framework for end-to-end testing of threat detection rules. Detonates attack techniques and verifies alerts in security platforms like…

High-interaction MitM SSH honeypot

Public Repo for Atomic Test Harness


Windows service that creates fake SMB sessions to simulate high-privilege user logons, luring attackers into honeypot machines for early detection…

Agent-based ransomware simulation toolkit for controlled detection testing across Windows endpoints and network assets, with a cross-platform…

Active deception tool that transparently migrates attackers from real targets to honeypots during exploitation and post-exploitation, supporting…

Timestomp Tool to flatten MAC times with a specific timestamp

Kill Any Antivirus Using Python For Windows Users .

SunnyDayBPF: eBPF-based post-syscall user-buffer telemetry deception research by Azizcan Daştan

Detection rule validation

CVE-2025-53690 POC

Menu bar app that monitors SSID changes to automatically reboot a Mac upon device snatching, providing a physical security countermeasure against…