
watcher
Detection reverse shell and kill it before trying shell.

Detection reverse shell and kill it before trying shell.

🐍 High-performance, multi-threaded YARA & IOC scanner

A host based IDS written in C# Targetted at Metasploit

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compatible with…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Header-only Windows x64 indirect syscall library. Zero CRT, zero IAT, VEH anti-BP, AMSI/ETW bypass, W^X memory, per-call dynamic stubs.

Memory API proxy via signed mozglue.dll

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

DARKSURGEON is a Windows packer project to empower incident response, digital forensics, malware analysis, and network defense.

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.

Free hands-on digital forensics labs for students and faculty

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…