MagiskTrustUserCerts
A Magisk/KernelSU module that automatically adds user certificates to the system root CA storeposh-dsc-windows-hardening
Windows OS Hardening with PowerShell DSCdisable-flutter-tls-verification
A Frida script that disables Flutter's TLS verificationCobaltWhispers
CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection, persistence and more, leveraging direct syscalls (SysWhispers2) to bypass EDR/AVee-outliers
Open-source framework to detect outliers in Elasticsearch eventsbinsnitch
Detect silent (unwanted) changes to files on your systempyCobaltHound
pyCobaltHound is an Aggressor script extension for Cobalt Strike which aims to provide a deep integration between Cobalt Strike and Bloodhound.frida-ios-playground
An iOS app that lets you practice your Frida skillsevtx-hunter
evtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files.Interceptor
Interceptor is a kernel driver focused on tampering with EDR/AV solutions in kernel spacebrown-bags
IOXY
MQTT intercepting proxydecompile-py2exe
Decompile py2exe Python 3 generated EXEsDInvisibleRegistry
DInvisibleRegistryblogposts
A repo to house files for our blogposts on blog.nviso.eucs2br-bof
codasm
Payload encoding utility to effectively lower payload entropy.cyber-security-llm-agents
A collection of agents that use Large Language Models (LLMs) to perform tasks common on our day to day jobs in cyber security.nviso-cti
nexus_5_bootloader_unpacker
A bootloader imgdata unpacker for Nexus 4, 5 and 7 smartphones as well as imgdata tool for Nexus 5.FileSearcher
logalert.py
Smart piping of command output to email for alerting.DLLoader
SEC599-Resources
SEC599
SEC599 supporting GitHub repositoryVerifiedBootRPi3
Verified Boot for RPi3cobalt-strike-notifier
YARA
Repository of YARA rules developed by NVISOansible-velociraptor
Ansible role for Velociraptor EDRcloud-security-automation
PowerShell scripts used in the "Incident response in the cloud/ foggy with a ray of sunshine" conference talkansible-sysmon
Ansible role for sysmonansible-auditbeat
Ansible role for auditbeat installansible-thehive
Ansible role for installing The Hive & CortexBitSight-Automation-Tool
BitSight Automation was developed to automate certain manual procedures and extract information such as ratings, assets, findings, etc. This tool also provides the possibility to collaborate with Scheduled Tasks and cronjobs.ansible-windowslogconfig
Ansible role for configuring Windows security logsansible-caldera
Ansible role for MITRE calderaassemblyline-service-cape
Assemblyline service build for CAPE's APIansible-elk
Ansible role for ELK stack installansible-winlogbeat
Ansible role for WinLogBeatassemblyline-service-python-exe-unpacker
Python exe unpacker serviceansible-covenant
Ansible role for Covenantassemblyline-service-urlscanio
URLScan.io AL serviceassemblyline-service-clamav
Assemblyline service which submits a file to ClamAV and displays the resultassemblyline-service-msg-extractor
Simple MSG extractor AssemblyLine serviceansible-nexusrepo
Ansible role for Nexus Repository OSSassemblyline-service-steg-finder
AssemblyLine service which scans for embedded data in image using StegExposeassemblyline-service-malware-bazaar
Assemblyline service fetching Malware Bazaar reportcaldex
Caldera exportation plugin to the MITRE ATT&CKâ„¢ Navigator.assemblyline-service-autoit-ripper
AutoIt unpacker serviceassemblyline-service-unfurl
Assemblyline service parsing a submitted URL to unshorten it.cortex.xsoar
The cortex.xsoar collection includes Ansible modules to help automate the management of Palo Alto Cortex XSOAR.Love Open Source and this site? Check out how you can help us