
CLR-Unhook
Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

Modular framework for Windows UAC bypass attacks and mitigation, featuring DLL hijacking, fileless execution, and real-time monitoring to detect and…

pySigma OpenSearch backend

CyberResponders is a terminal-based cybersecurity training game that enables players to respond to different cyber incident scenarios. Here, they…

Picking up processes that have triggered ASR related to CVE-2022-30190

Zeek package for tracking long connections to report them before they have completed.

:dart: Prevent RubberDucky (or other keystroke injection) attacks

This repository contains a list of new remediation scripts.

Real-time guardrails for Claude Code tool calls.

Java agent that transforms a vulnerable class to block exploitation of CVE-2024-43044 in Jenkins controllers, with optional forced shutdown on…

A powerful and flexible tool to apply active attacks for disrupting stegomalware

Panic button for protection against cold boot attacks

a Fedora remix focused on pentesting and purple hat tooling

Spartacus DLL/COM Hijacking Toolkit

Helps defenders find their WSUS configurations in the wake of CVE-2025-59287

Yet another Ransomware gang tracker

Red Team C code repo

Create fake certs for binaries using windows binaries and the power of bat files