
ToolShell-Honeypot
Honeypot for CVE-2025-53770 aka ToolShell

Honeypot for CVE-2025-53770 aka ToolShell

CVE-2019-0708 bluekeep 漏洞检测

CVE-2020-16898 (Bad Neighbor) Microsoft Windows TCP/IP Vulnerability Detection Logic and Rule

8 Lessons, Kick-start Your Cybersecurity Learning.

⭐⭐ Join us at SNIA SDC for the SMB3 IO Lab (September 28 - October 1, 2026), see upcoming Interoperability Events

C# post-exploitation tool for abusing Microsoft Configuration Manager (SCCM) to perform lateral movement, credential gathering, and NTLM…

CVE-2024-38200 & CVE-2024-43609 - Microsoft Office NTLMv2 Disclosure Vulnerability

NCC Group Template for the Microsoft Threat Modeling Tool 2016 for Automotive Security

Scanners List - Microsoft Windows SMBv3 Remote Code Execution Vulnerability (CVE-2020-0796)

这是一个用于防御巡检的 CVE-2026-41089 检测脚本。该漏洞是 Microsoft 在 2026 年 5 月安全更新中披露的 Windows Netlogon 远程代码执行漏洞。

A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability.

A wireshark plugin to instrument ETW

基于asyncio(协程)的CVE-2020-0796 速度还是十分可观的,方便运维师傅们对内网做下快速检测。

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.


Check for events that indicate non compatible devices -> CVE-2020-1472

CLI tool to audit Azure security posture, RBAC, NSGs, storage, identity, and encryption