Australia

pat_h/to/file

Expert
@pathtofile

path@tofile.dev

bad-bpf. A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29

695

Sealighter. Sysmon-Like research tool for ETW

394

SealighterTI. Combining Sealighter with unpatched exploits to run the Threat-Intelligence ETW Provider

208

PPLRunner. Run Processes as PPL with ELAM

184

bpf-hookdetect. Dectect syscall hooking using eBPF

169

siemcraft. Security Information and Event Management in Minecraft

121

commandline_cloaking. A collection of projects demonstrating various commandline cloaking techniques on Linux

62

bpf-pipesnoop. Example program using eBPF to log data being based in using shell pipes

41

tf_wireguard. Simple Terraform Scripts to setup a WireGuard server on various cloud providers.

26

SimpleAmsiProvider. A simple provider to analyse what gets passed into Microsoft's Anti-Malware Scan Interface

17

toucli. Use TouchID and the Secure Enclave to encrypt data from the commandline.

17

ios_configuration_profiles. This repo contains the parsed PList data from [Apple's Developer Configuration Profiles](https://developer.apple.com/bug-reporting/profiles-and-logs/?platform=ios).

9

ctlwatcher. Monitor Certificate Transparency logs for domains matching regexes.

8

https.server. Python SimpleHTTPServer wrapped in TLS

8

bpf-uprobedbg. C

6

ld_preload_go. Simple example of creating an `LD_PRELOAD` library in Go that hooks LibC's main function.

5

cookiecache. Simplify getting and using cookies from the browser to use in Python.

4

ebpf-pinned-fentry. Example how to run eBPF probes without a usermode process using fentry

4

etw_watcher. Using GitHub Actions to create commit diffs

4

terraform-provider-bitlaunch. BitLaunch Terraform Provider

3

Presentations. A Repo to hold slides from presentations, etc.

3

etwRunner. Basic KrabsETW runner template

2

PowerInject. Inject Interactive PowerShell into an arbitrary process

2

dockenv. Dockenv - Run python in docker the easy way

2

sgproxy. Basic HTTP/S proxy. Created to add HTTP Auth to a request from a client that doesn't support supplying auth in URL, for example VScode's Juypyter Notebook Server browser.

1

sigstore-watcher. Watches SigStore Code Signing Logs

1

etrace. strace-like logging using bpftrace and eBPF

1

Puppeteer-Stealth-Docker. This is a simple example of how do stealthy headless chrome webscraping from a Docker container.

1

pyauditlogger. Auto-Add Python 3.8 audit hooks to all python scripts

1

hijack-watcher. Rust version of HijackWatcher

1

volatility2-profile-ubuntu2104. A Profile for Volatility 2 Matching Ubuntu 21.04

1

Import-Scanner. This tool scans all PEs in a directory for the import `CveEventWrite`, a new function that Writes CVE details to ETW and the Event Log

1
32
Apply