
BearFTP
Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.

End-to-end vulnerability management lifecycle on Azure Windows Server 2025. Features OS patching and network-level compensating controls (NSG) to…

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

A portable C# utility for enumerating local and remote windows sessions

Technical write-up and analysis of PrintNightmare (CVE-2021-1675 / CVE-2021-34527), covering RCE/LPE exploitation, detection via Windows event logs,…

Step-by-step remediation guide for CVE-2013-3900 WinVerifyTrust vulnerability on Windows Server 2019, including registry fix, reboot, and…

Documentation and scripts to properly enable Windows event logs.

Web-based tool for managing and deploying Sysmon configurations across Windows endpoints via agentless (WMI/SMB) or agent-based methods, with remote…

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

Defensive Windows security application providing compensating controls for CVE-2017-0144 (EternalBlue/MS17-010) through SMB monitoring, attack…

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

Script to update Windows Recovery Environment to patch against CVE-2022-41099

Restore the integrity of the parent 'inetpub' folder following security implications highlighted by CVE-2025-21204.

Azure-based client inventory and drift detection tool that collects Windows configuration data (antivirus, patching, Bitlocker) into LogAnalytics for…

PowerShell script to apply Microsoft's recommended registry-based workaround for CVE-2023-36884, mitigating remote code execution risk on Windows…

Provides BigFix Fixlets and analyses to detect Log4j vulnerabilities (CVE-2021-44228, CVE-2021-45046, CVE-2021-45105) across Windows and Linux…

PowerShell-based security toolkit for small-to-medium enterprises, providing automated alerts, Active Directory hardening, Windows Event Forwarding,…

Permanent fix for Intel NUC WinRing0 vulnerable driver (CVE-2020-14979) reinstallation via Windows Update