This is your work, valued
PowerShellArsenal. A PowerShell Module Dedicated to Reverse Engineering
899CimSweep. CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.
656PIC_Bindshell. Position Independent Windows Shellcode Written in C
298WMI_Backdoor. A PoC WMI backdoor presented at Black Hat 2015
277WDACTools. A PowerShell module to facilitate building, configuring, deploying, and auditing Windows Defender Application Control (WDAC) policies
254PSSysmonTools. Sysmon Tools for PowerShell
233PSReflect. Easily define in-memory enums, structs, and Win32 functions in PowerShell
228WinPETools. A module designed to simplify the creation, customization, and deployment of bootable Windows Preinstallation Environment (WinPE) images.
155AntimalwareBlight. Execute PowerShell code at the antimalware-light protection level.
141BHUSA2018_Sysmon. All materials from our Black Hat 2018 "Subverting Sysmon" talk
134DeviceGuardBypassMitigationRules. A reference Device Guard code integrity policy consisting of FilePublisher deny rules for published Device Guard configuration bypasses
116PoCSubjectInterfacePackage. A proof-of-concept subject interface package (SIP) used to demonstrate digital signature subversion attacks.
100TCGLogTools. A set of tools to retrieve and parse TCG measured boot logs. Microsoft refers to these as Windows Boot Confirguration Logs (WBCL). In order to retrieve these logs, you must be running at least Windows 8 with the TPM enabled.
77WDACPolicies. A collection of Windows software baseline notes with corresponding Windows Defender Application Control (WDAC) policies
63BCD. BCD is a module to interact with boot configuration data (BCD) either locally or remotely using the ROOT/WMI:Bcd* WMI classes. The functionality of the functions in this module mirror that of bcdedit.exe.
62WindowsEventLogMetadata. Event metadata collected across all manifest-based ETW providers on Window 10 1903
32ShellcodeExec. A simple shellcode runner
23CatalogTools. A PowerShell module to assist in parsing and managing catalog files.
22capstone. Capstone disassembly framework: Core + Python + Ocaml + Java + C# bindings
18UnicornPowerShell. A PowerShell binding for the Unicorn Engine
17MSFTTraceMessageFormat. All TMF files that I extracted from Microsoft PDBs.
14mattifestation.
7