
TiEtwAgent
PoC memory injection detection agent based on ETW, for offensive and defensive research purposes

PoC memory injection detection agent based on ETW, for offensive and defensive research purposes

Kernel-mode filter driver that monitors ConDrv traffic to detect mimikatz execution in real-time, logging detection events via ETW for incident…

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

PowerShell script that automatically tests CMD bypass methods on Windows, evaluates results, calculates a security score, and provides hardening…

Lightweight, container-free sandbox for running commands with network and filesystem restrictions

The Sigma command line interface based on pySigma

VBScript & VBA source-to-source deobfuscator with partial-evaluation

End-to-end cybersecurity project demonstrating detection and mitigation of CVE-2024-38063 using IDS, host-based monitoring, and virtual lab attack…

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.