Pinned Repositories
CnC
Command & Control platform for own needs with tiny C++ agent (likely to bypass EDR).
DInvoke_PoC
Hardened Proof of Concept of D/Invoke Process Injection malware
DotNetInject
Code samples of .NET shellcode injections, weaponized for use via WebDav and mshta.exe.
easy-hollow
Automated build for process hollowing shellcode loader. Build on top of TikiTorch and donut projects.
Invoke-WinSecure
PowerShell script that performs registry, network, service checks. Solves weaknesses of default Windows settings.
malware_lab_notebooks
nebula
Transformer Neural Network from Dynamic Malware Detection
quo.vadis
Hybrid Machine Learning Model for Malware Detection based on Windows Kernel Emulation
slp
Shell Language Processing (SLP). Pre-processing of sh/bash/zsh/.. commands for Machine Learning models.
SysmonRNN
All necessary code in order to feed Sysmon data into Recurrent Neural Network
dtrizna's Repositories
dtrizna/DInvoke_PoC
Hardened Proof of Concept of D/Invoke Process Injection malware
dtrizna/quo.vadis
Hybrid Machine Learning Model for Malware Detection based on Windows Kernel Emulation
dtrizna/slp
Shell Language Processing (SLP). Pre-processing of sh/bash/zsh/.. commands for Machine Learning models.
dtrizna/nebula
Transformer Neural Network from Dynamic Malware Detection
dtrizna/SysmonRNN
All necessary code in order to feed Sysmon data into Recurrent Neural Network
dtrizna/easy-hollow
Automated build for process hollowing shellcode loader. Build on top of TikiTorch and donut projects.
dtrizna/malware_lab_notebooks
dtrizna/counterfit
a CLI that provides a generic automation layer for assessing the security of ML models
dtrizna/malware_lab_files
dtrizna/QuasarNix
Reverse Shell Detection with Machine Learning
dtrizna/RuralBishop
D/Invoke port of UrbanBishop
dtrizna/talks
dtrizna/ai_security_labs
dtrizna/AQUARMOURY
My musings in C and offensive tooling
dtrizna/awesome-ml-for-cybersecurity
:octocat: Machine Learning for Cyber Security
dtrizna/Charcuterie
Data Scientists Go To Jupyter
dtrizna/docker-py
Example of Python applications (HTTP server and Load Balancer) to be executed as Docker containers.
dtrizna/ember
Elastic Malware Benchmark for Empowering Researchers
dtrizna/eql_hunt
Code to automate execution and collection of complex EQL queries.
dtrizna/GTFOBins.github.io
GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems
dtrizna/latma
dtrizna/misc
dtrizna/PyScriptTests
dtrizna/pyvelociraptor
PyVelociraptor contains the python bindings for the Velociraptor API.
dtrizna/Ransomware-Samples
Small collection of Ransomware organized by family.
dtrizna/RNN
Recurrent Neural Networks and supporting code (preprocessing, other classical models).
dtrizna/Sharp-Suite
My musings with C#
dtrizna/slack-dm-sender
Send a message to multiple Slack users in DM at once.
dtrizna/speakeasy
Windows kernel and user mode emulation.
dtrizna/trustworthy_ai_labs