
SkillsGuard
Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks…

An open-source post-exploitation framework for students, researchers and developers.

Attack and defend active directory using modern post exploitation adversary tradecraft activity

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2…

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

Modular attack toolkit exploiting Azure DevOps REST API for reconnaissance, privilege escalation, and persistence using stolen cookies or PATs.

Linux Persistence Detection, Hunting and Artifact Collection script

Python-based keylogger and surveillance tool with Telegram C2, capturing keystrokes, screenshots, webcam, audio, clipboard, and system activity for…

A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

Remote administration service which uses twitter as a command and control server