
C2-detection-manjusaka
Detection of Manjusaka C2 framework

Detection of Manjusaka C2 framework

An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what…

Hunting CVE-2018-13379

Detect and respond to Cobalt Strike beacons using ETW.

DFIR investigation resources for CVE-2021-36934, covering DLL hijacking, privilege-escalation detection, and forensic analysis of affected Windows…

** DISPUTED ** 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the…

Detection and Mitigation script for CVE-2021-36934 (HiveNightmare aka. SeriousSam)

Sigma detection rule for MiniPlasma (CVE-2020-17103)

A temporary mitigation against copy_fail variant (copyfail2_electric_boogaloo) - Unprivileged Linux LPE via xfrm ESP-in-UDP MSG_SPLICE_PAGES no-COW…

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

The TTPForge is a Cybersecurity Framework for developing, automating, and executing attacker Tactics, Techniques, and Procedures (TTPs).

Create and enumerate hidden desktops.

Scripts for performing and detecting parent PID spoofing

EDRUnChoker - fileless WMI defense that removes EDRChoker QoS throttling policies

Hot-patch CVE-2021-44228 by exploiting the vulnerability itself.

7-Zip CVE-2022-29072 Mitigation - CHM file - This script detects if the .chm file exists and removes it.

Security advisory detailing a critical authentication vulnerability in Copilot where user IDs are switched, enabling unauthorized account access and…