Skip to content
View thesubtlety's full-sized avatar

Block or report thesubtlety

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

Nuke It From Orbit - remove AV/EDR with physical access

Go 170 11 Updated Oct 31, 2024

Bounces when a fish bites - Evilginx database monitoring with exfiltration automation

Python 156 12 Updated Jun 9, 2024

🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.

Python 31 1 Updated Oct 13, 2024

A high-performance port spoofing tool built in Rust. Confuse port scanners with dynamic service emulation across all ports. Features customizable signatures, efficient async handling, and easy tra…

Rust 228 11 Updated Oct 27, 2024

Additional active scan checks for BURP

Kotlin 19 1 Updated Oct 3, 2024

Chrome extension for automating CSPT discovery

TypeScript 43 2 Updated Oct 7, 2024

Tool to decrypt App-Bound encrypted keys in Chrome 127+, using the IElevator COM interface with path validation and encryption protections.

C++ 211 42 Updated Oct 30, 2024

Sublime rules for email attack detection, prevention, and threat hunting.

YAML 254 47 Updated Nov 2, 2024

The `boring` SSH tunnel manager

Go 711 21 Updated Nov 2, 2024

Awesome things from the community

709 32 Updated Sep 18, 2024

A collection of projects designed to help developers quickly get started with building deployable applications using the Anthropic API

TypeScript 6,455 871 Updated Oct 29, 2024

A stealthy ELF loader - no files, no execve, no RWX

C 155 9 Updated Dec 31, 2023

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

PowerShell 6 1 Updated Oct 5, 2024

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

PowerShell 703 116 Updated Nov 2, 2024

Sparrow.ps1 was created by CISA's Cloud Forensics team to help detect possible compromised accounts and applications in the Azure/m365 environment.

PowerShell 1,417 182 Updated Dec 27, 2022

Rapidly Search and Hunt through Windows Forensic Artefacts

Rust 2,851 260 Updated Oct 31, 2024

Practical Windows Forensics Training

PowerShell 615 103 Updated Feb 29, 2024

Repository of attack and defensive information for Business Email Compromise investigations

225 26 Updated Aug 25, 2024

A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID

PowerShell 333 37 Updated Nov 2, 2024

A BYOSI (Bring-Your-Own-Script-Interpreter) Rapid Payload Deployment Toolkit

Rust 71 6 Updated Aug 9, 2024

Halberd : Multi-Cloud Security Testing Tool to execute attacks across multiple surfaces via a intuitive web interface.

Python 179 11 Updated Nov 1, 2024

A web application to streamline the development of STIGs from SRGs

Ruby 63 16 Updated Oct 2, 2024

Open Breach and Attack Simulation Platform

Java 655 69 Updated Nov 2, 2024

Save toil in security operations with: Detection & Intelligence Analysis for New Alerts (D.I.A.N.A. )

Python 146 16 Updated Sep 4, 2024

Tooling backed by an LLM for performing natural language searches against compiled target binaries. Search for encryption code, password strings, vulnerabilities, etc.

Python 142 39 Updated Apr 10, 2024

Java archive implant toolkit.

Java 54 4 Updated Sep 12, 2024

Create a break glass role for emergency use in order to limit AWS production account access. Configure automatic alerts and logging of activities in the role to secure its use in production environ…

TypeScript 164 9 Updated Nov 13, 2023

A set of policies, standards and control procedures with mapping to HIPAA, NIST CSF, PCI DSS, SOC2, FedRAMP, CIS Controls, and more.

JavaScript 291 87 Updated Jun 18, 2024

Compliance automation framework, focused on SOC2

Go 1,315 246 Updated Jul 21, 2022

RedCloudOS is a Cloud Adversary Simulation Operating System for Red Teams to assess the Cloud Security of Leading Cloud Service Providers (CSPs)

Shell 578 80 Updated Jun 4, 2024
Next