
CVE-2024-49138-SOC-Investigation
SOC investigation of CVE-2024-49138 exploitation involving brute-force activity, PowerShell execution, malicious payload analysis, privilege…

SOC investigation of CVE-2024-49138 exploitation involving brute-force activity, PowerShell execution, malicious payload analysis, privilege…

Enterprise vulnerability management on Azure — Terraform-deployed Nessus scanner, credentialed scanning, CVE-2013-3900 remediation with verified…

PowerShell-based provisioning framework for deploying complex lab environments on Hyper-V and Azure. Supports Windows, Linux, and products like AD,…

PowerShell exploit for CVE-2024-0670, abusing CheckMK Agent MSI repair to escalate from low-privileged user to SYSTEM on Windows targets. Designed…

A personal Windows SOC suite built in PowerShell — monitors network connections, resource usage, scheduled tasks and power events with severity…

Using Struts2 and PowerShell to recreate CVE-2017-5638 OGNL Injection vulnerability.

Proof-of-concept security demo illustrating how PowerShell can create trusted-looking Windows toast notifications chained together with…

SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated…

High fidelity defensive security lab simulating a DoD aligned enterprise network with Active Directory, VLAN segmentation, STIG based hardening,…

Windows Local Privilege Escalation Cookbook

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

Automated remediation of CVE-2025-53783 (Teams RCE) using PowerShell

Proof-of-concept exploits for CVE-2022-31199, a critical .NET deserialization RCE in Netwrix Auditor. Includes Python and PowerShell scripts, payload…

Reproducible lab for CVE-2020-0610 (BlueGate) - Windows RD Gateway UDP/DTLS remote code execution vulnerability. Includes PowerShell scripts, setup…

Custom PowerShell module to setup an Active Directory lab environment to practice penetration testing.

Hands-on red-team obfuscation workshop teaching AMSI bypass, ETW evasion, and payload obfuscation with PowerShell, Visual Basic, and C# to evade…

Automate the creation of a lab environment complete with security tooling and logging best practices

An exercise to practice deobfuscating PowerShell Scripts.