Lists (8)
Sort Name ascending (A-Z)
Stars
Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown
When good OAuth apps go rogue. Documents observed OAuth application tradecraft
A honey token manager and alert system for AWS.
Canarytokens helps track activity and actions on your network.
Records an executable's network activity into a Full Packet Capture file (.pcap) and much more.
SACL Scanner is a tool designed to scan and analyze SACLs.
eBPF implementation that runs on top of Windows
Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/
Simple script to extract useful informations from the combo BloodHound + Neo4j
PurpleLab is an efficient and readily deployable lab solution, providing a swift setup for cybersecurity professionals to test detection rules, simulate logs, and undertake various security tasks,…
A cross-platform tool to parse and describe the contents of a raw ntSecurityDescriptor structure.
Invoke-ArgFuscator is an open-source, cross-platform PowerShell module that helps generate obfuscated command-lines for common system-native executables.
Customizable Linux Persistence Tool for Security Research and Detection Engineering.
View HTTP/HTTPS requests made by any Linux program
Linux running inside a PDF file via a RISC-V emulator
ADExplorerSnapshot.py is an AD Explorer snapshot parser. It is made as an ingestor for BloodHound, and also supports full-object dumping to NDJSON.
In this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (a SIEM tool).
🔔 Get notified on the addition or removal of roles and permissions in Microsoft Entra ID and Azure 🔔
Azure administrative tiering based on known attack paths
Unicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, PowerPC, RiscV, S390x, TriCore, X86)
Monitors ETW for security relevant syscalls maintaining the set called by each unique process
The FLARE team's open-source tool to identify capabilities in executable files.