WTF are these binaries doing?! A list of benign applications that mimic malicious behavior.
☆173Mar 30, 2025Updated last year
Alternatives and similar repositories for wtfbins
Users that are interested in wtfbins are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Proof-of-Concept to evade auditd by tampering via ptrace☆19Aug 3, 2023Updated 3 years ago
- ☆27Feb 6, 2022Updated 4 years ago
- BadExclusions is a tool to identify folder custom or undocumented exclusions on AV/EDR☆21Feb 8, 2024Updated 2 years ago
- BOF for C2 framework☆45Nov 9, 2024Updated last year
- ☆264May 9, 2024Updated 2 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- ☆11Jun 26, 2024Updated 2 years ago
- Purple Team Resources for Enterprise Purple Teaming: An Exploratory Qualitative Study by Xena Olsen.☆680Jun 14, 2023Updated 3 years ago
- Rules generated from our investigations.☆214Jul 8, 2026Updated 3 months ago
- Notion as a platform for offensive operations☆1,175May 21, 2023Updated 3 years ago
- Convert Microsoft Defender Antivirus Signatures (VDM) into a SQL DB☆27Jun 27, 2025Updated last year
- Ludus roles to deploy ASR rules and MDI auditing settings☆25Aug 5, 2025Updated last year
- Repository of Microsoft Driver Block Lists based off of OS-builds☆45Apr 14, 2024Updated 2 years ago
- Extracts Azure authentication tokens from PowerShell process minidumps.☆25May 20, 2023Updated 3 years ago
- Using Microsoft 365 App Passwords for persistence☆23Sep 2, 2020Updated 6 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A simple PE loader.☆27Dec 9, 2022Updated 3 years ago
- ☆237Jun 10, 2025Updated last year
- Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)☆265Jun 29, 2024Updated 2 years ago
- Detect EDR's exceptions by inspecting processes' loaded modules☆133Mar 15, 2024Updated 2 years ago
- The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifa…☆664Jul 14, 2026Updated 2 months ago
- ☆21May 8, 2022Updated 4 years ago
- ☆122Jan 30, 2024Updated 2 years ago
- An example of how a driver can register a handle creation callback.☆16Jun 12, 2023Updated 3 years ago
- The cActiveDirectorySecurity module contains PowerShell Functions which are designed to report on and manipulate Access Control Lists on …☆11Aug 31, 2018Updated 8 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- A PoC of the ContainYourself research presented in DEFCON 31, which abuses the Windows containers framework to bypass EDRs.☆317Aug 31, 2023Updated 3 years ago
- Purple Team Exercise Framework☆823Apr 9, 2026Updated 6 months ago
- quASAR: ASAR manipulation made easy☆40Sep 7, 2022Updated 4 years ago
- A collection of art inspired by the world of cybersecurity and hacking culture.☆44May 14, 2025Updated last year
- ☆384Aug 7, 2023Updated 3 years ago
- Production-ready Windows 10 & 11 Exploit Protection policy aligned with Microsoft Defender and DISA STIG baselines.☆13Updated this week
- ☆20May 30, 2025Updated last year
- Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows…☆2,139Dec 11, 2024Updated last year
- Indicators of Normality☆11Jul 22, 2022Updated 4 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- WptsExtensions.dll for exploiting DLL hijacking of the task scheduler.☆57Jun 30, 2021Updated 5 years ago
- A tool for checking if MFA is enabled on multiple Microsoft Services☆1,708Apr 13, 2026Updated 5 months ago
- Extension functionality for the NightHawk operator client☆27Nov 3, 2023Updated 2 years ago
- ☆104Oct 7, 2023Updated 3 years ago
- ☆91Jul 18, 2023Updated 3 years ago
- Documentation and scripts to properly enable Windows event logs.☆723Oct 3, 2025Updated last year
- Scraping Kit is made up of several tools for scraping services for keywords, useful for initial enumeration of Domain Controllers or if y…☆102Jul 7, 2023Updated 3 years ago