countercept topic
chainsaw
Rapidly Search and Hunt through Windows Forensic Artefacts
ppid-spoofing
Scripts for performing and detecting parent PID spoofing
python-exe-unpacker
A helper script for unpacking and decompiling EXEs compiled from python code.
doublepulsar-c2-traffic-decryptor
A python2 script for processing a PCAP file to decrypt C2 traffic sent to DOUBLEPULSAR implant
CallStackSpoofer
A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)
doublepulsar-detection-script
A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.
doublepulsar-usermode-injector
A utility to use the usermode shellcode from the DOUBLEPULSAR payload to reflectively load an arbitrary DLL into another process, for use in testing detection techniques or other security research.
LinuxCatScale
Incident Response collection and processing scripts with automated reporting scripts
detectree
Data visualization for blue teams