adeleg. Active Directory delegation management tool
525ntsec. Standalone tool to explore the security model of Windows and its NT kernel. Use it to introspect privilege assignments and access right assignments, enumerate attack surfaces from the point of view of a sandboxed process, etc.
33evtq. Windows eventlog formatting, live fetching and querying utility in C
21winsddl. Windows Security Descriptor Definition Language (SDDL) parser and formatter
20libiris. libiris is a cross-platform sandboxing library, intended as a not-for-production harness with a low barrier to entry
17win32k-mitigation. A test project to try the new win32k.sys system call filtering mitigation in Windows 10
16lsobj. Lists all visible objects in the Windows kernel object namespace, a command-line WinObj
16captrace. Lists capabilities used by processes on your system as they are requested, to assist in the task of creating custom hardened profiles for containers and sandboxes.
13muslkl. A unikernel builder based on MUSL + LKL, designed to run any vanilla application inside an SGX enclave
10nt-object-types. Toy project to explore the NT kernel's object types and their security access rights
7dracut-dropbear-unlock. A minimalist dracut module that allows you to remotely unlock an encrypted root partition during boot.
5windows-service-dll. Minimal Windows service boilerplate packaged as DLL
5windows-service. Minimal Windows service boilerplate
5tristitude. A simple process security policy enumerator. This project has been superseded by https://github.com/mtth-bfft/ntsec , which now has the same functionalities and many more :)
5seccomp-dump. A small utility to fetch the raw seccomp BPF filter program used by a thread from the kernel
4dyndnsmon. Live monitor for failed dynamic DNS updates on Windows Server
3kblist. Windows Update website crawler to list security updates by version and type (cumulative/non-cumulative)
3tpm-otp. A minimal tool that communicates with your TPM during boot, to display a one-time password and prove bootchain integrity.
3seccomp-analyze. A seccomp BPF filter verifier written in Prolog, to parse, analyze and list system calls and arguments allowed by a given filter.
3repadmin-parser. Minimal Python parser for Microsoft's repadmin replication metadata listings
2simplvpn. A standalone script to manage OpenVPN server and client configurations.
2ipc-benchmarks. Benchmarks for various IPC mechanisms on various OSes
2dotfiles. .files, sensible default configuration files and customisations that I use on all my machines
1sandboxing-pocs. Various not-for-production proofs of concept around sandboxing
1lapsus. A standalone miniature tool to reset the local administrator password of each computer in your Windows fleet to a random value, stored encrypted in a central registry (on a network share, for instance).
1