Highlights
- Pro
Lists (20)
Sort Name ascending (A-Z)
Stars
Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.
This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.
Simple (relatively) things allowing you to dig a bit deeper than usual.
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
Deep Linux runtime visibility meets Wireshark
The Linux port of the Sysinternals Sysmon tool.
Library and tools to access the Windows New Technology File System (NTFS)
Monitors for DCSYNC and DCSHADOW attacks and create custom Windows Events for these events.
ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits
Tool designed to exfiltrate OneDrive Business OCR Data
Enumerate Windows Defender threat families and dump their names according category
This repo will contain the core detection, only for Cobaltstrike's leaked versions. Non-leaked version detections wont be shared
List the ETW provider(s) in the registration table of a process.
This tool have the power to hide any PID/directory in the Linux kernel
mthcht / SealighterTI
Forked from pathtofile/SealighterTICombining Sealighter with unpatched exploits to run the Threat-Intelligence ETW Provider
mthcht / PSBits
Forked from gtworek/PSBitsSimple (relatively) things allowing you to dig a bit deeper than usual.
mthcht / snoopy
Forked from a2o/snoopySnoopy Command Logger is a small library that logs all program executions on your Linux/BSD system.
mthcht / LiME
Forked from 504ensicsLabs/LiMELiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, such as those powered by Android. The tool supports acquir…