
powerview.py
Enumerate and attack Active Directory with LDAP session persistence, ACL abuse, Kerberoasting/ASREProasting, shadow credentials, RBCD, and NTLM relay.

Enumerate and attack Active Directory with LDAP session persistence, ACL abuse, Kerberoasting/ASREProasting, shadow credentials, RBCD, and NTLM relay.

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

CLI and Go framework for end-to-end testing of threat detection rules. Detonates attack techniques and verifies alerts in security platforms like…


Transparent proxy that decrypts SSL traffic and prints out IRC messages.

Curated collection of Hashcat password-cracking rules with benchmark data, designed to help red teams and penetration testers crack complex passwords…

First iteration of ML based Feedback WAF

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

Kernel-level iptables backdoor that accepts all packets with the RFC 3514 evil bit set, bypassing firewall rules. Includes in-tree and out-of-tree…

Providing Azure pipelines to create an infrastructure and run Atomic tests.

Client/server scripts designed to test outbound (egress) firewall rules.

Ansible role to configure redirectors for red team C2

CVE-2026-24207 — NVIDIA Triton SageMaker auth bypass to unauth RCE. Detection script, bypass demo, RCE-chain PoC, and IDS rules.

Network monitoring tool that maps process-to-network connections, identifies cloud providers, and detects beaconing activity