bad-bpf. A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29
695Sealighter. Sysmon-Like research tool for ETW
394SealighterTI. Combining Sealighter with unpatched exploits to run the Threat-Intelligence ETW Provider
208PPLRunner. Run Processes as PPL with ELAM
184bpf-hookdetect. Dectect syscall hooking using eBPF
169siemcraft. Security Information and Event Management in Minecraft
121commandline_cloaking. A collection of projects demonstrating various commandline cloaking techniques on Linux
62bpf-pipesnoop. Example program using eBPF to log data being based in using shell pipes
41tf_wireguard. Simple Terraform Scripts to setup a WireGuard server on various cloud providers.
26SimpleAmsiProvider. A simple provider to analyse what gets passed into Microsoft's Anti-Malware Scan Interface
17toucli. Use TouchID and the Secure Enclave to encrypt data from the commandline.
17ios_configuration_profiles. This repo contains the parsed PList data from [Apple's Developer Configuration Profiles](https://developer.apple.com/bug-reporting/profiles-and-logs/?platform=ios).
9ctlwatcher. Monitor Certificate Transparency logs for domains matching regexes.
8https.server. Python SimpleHTTPServer wrapped in TLS
8bpf-uprobedbg. C
6ld_preload_go. Simple example of creating an `LD_PRELOAD` library in Go that hooks LibC's main function.
5cookiecache. Simplify getting and using cookies from the browser to use in Python.
4ebpf-pinned-fentry. Example how to run eBPF probes without a usermode process using fentry
4etw_watcher. Using GitHub Actions to create commit diffs
4terraform-provider-bitlaunch. BitLaunch Terraform Provider
3Presentations. A Repo to hold slides from presentations, etc.
3etwRunner. Basic KrabsETW runner template
2PowerInject. Inject Interactive PowerShell into an arbitrary process
2dockenv. Dockenv - Run python in docker the easy way
2sgproxy. Basic HTTP/S proxy. Created to add HTTP Auth to a request from a client that doesn't support supplying auth in URL, for example VScode's Juypyter Notebook Server browser.
1sigstore-watcher. Watches SigStore Code Signing Logs
1etrace. strace-like logging using bpftrace and eBPF
1Puppeteer-Stealth-Docker. This is a simple example of how do stealthy headless chrome webscraping from a Docker container.
1pyauditlogger. Auto-Add Python 3.8 audit hooks to all python scripts
1hijack-watcher. Rust version of HijackWatcher
1volatility2-profile-ubuntu2104. A Profile for Volatility 2 Matching Ubuntu 21.04
1Import-Scanner. This tool scans all PEs in a directory for the import `CveEventWrite`, a new function that Writes CVE details to ETW and the Event Log
1