This is your work, valued

Paris, France

Matthieu Buffet

Expert
@mtth-bfft

adeleg. Active Directory delegation management tool

525

ntsec. Standalone tool to explore the security model of Windows and its NT kernel. Use it to introspect privilege assignments and access right assignments, enumerate attack surfaces from the point of view of a sandboxed process, etc.

33

evtq. Windows eventlog formatting, live fetching and querying utility in C

21

winsddl. Windows Security Descriptor Definition Language (SDDL) parser and formatter

20

libiris. libiris is a cross-platform sandboxing library, intended as a not-for-production harness with a low barrier to entry

17

win32k-mitigation. A test project to try the new win32k.sys system call filtering mitigation in Windows 10

16

lsobj. Lists all visible objects in the Windows kernel object namespace, a command-line WinObj

16

captrace. Lists capabilities used by processes on your system as they are requested, to assist in the task of creating custom hardened profiles for containers and sandboxes.

13

muslkl. A unikernel builder based on MUSL + LKL, designed to run any vanilla application inside an SGX enclave

10

nt-object-types. Toy project to explore the NT kernel's object types and their security access rights

7

dracut-dropbear-unlock. A minimalist dracut module that allows you to remotely unlock an encrypted root partition during boot.

5

windows-service-dll. Minimal Windows service boilerplate packaged as DLL

5

windows-service. Minimal Windows service boilerplate

5

tristitude. A simple process security policy enumerator. This project has been superseded by https://github.com/mtth-bfft/ntsec , which now has the same functionalities and many more :)

5

seccomp-dump. A small utility to fetch the raw seccomp BPF filter program used by a thread from the kernel

4

dyndnsmon. Live monitor for failed dynamic DNS updates on Windows Server

3

kblist. Windows Update website crawler to list security updates by version and type (cumulative/non-cumulative)

3

tpm-otp. A minimal tool that communicates with your TPM during boot, to display a one-time password and prove bootchain integrity.

3

seccomp-analyze. A seccomp BPF filter verifier written in Prolog, to parse, analyze and list system calls and arguments allowed by a given filter.

3

repadmin-parser. Minimal Python parser for Microsoft's repadmin replication metadata listings

2

simplvpn. A standalone script to manage OpenVPN server and client configurations.

2

ipc-benchmarks. Benchmarks for various IPC mechanisms on various OSes

2

dotfiles. .files, sensible default configuration files and customisations that I use on all my machines

1

sandboxing-pocs. Various not-for-production proofs of concept around sandboxing

1

lapsus. A standalone miniature tool to reset the local administrator password of each computer in your Windows fleet to a random value, stored encrypted in a central registry (on a network share, for instance).

1