
UnderlayCopy
PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

A little tool to play with Azure Identity - Azure and Entra ID lab creation tool. Blog: https://medium.com/@iknowjason/sentinel-for-purple-teaming-1…

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Tool to create hidden registry keys.