Pinned Repositories
bad-bpf
A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29
bpf-hookdetect
Dectect syscall hooking using eBPF
bpf-pipesnoop
Example program using eBPF to log data being based in using shell pipes
commandline_cloaking
A collection of projects demonstrating various commandline cloaking techniques on Linux
PPLRunner
Run Processes as PPL with ELAM
Presentations
A Repo to hold slides from presentations, etc.
Sealighter
Sysmon-Like research tool for ETW
SealighterTI
Combining Sealighter with unpatched exploits to run the Threat-Intelligence ETW Provider
siemcraft
Security Information and Event Management in Minecraft
toucli
Use TouchID and the Secure Enclave to encrypt data from the commandline.
pathtofile's Repositories
pathtofile/bad-bpf
A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29
pathtofile/Sealighter
Sysmon-Like research tool for ETW
pathtofile/SealighterTI
Combining Sealighter with unpatched exploits to run the Threat-Intelligence ETW Provider
pathtofile/bpf-hookdetect
Dectect syscall hooking using eBPF
pathtofile/commandline_cloaking
A collection of projects demonstrating various commandline cloaking techniques on Linux
pathtofile/tf_wireguard
Simple Terraform Scripts to setup a WireGuard server on various cloud providers.
pathtofile/toucli
Use TouchID and the Secure Enclave to encrypt data from the commandline.
pathtofile/ctlwatcher
Monitor Certificate Transparency logs for domains matching regexes.
pathtofile/https.server
Python SimpleHTTPServer wrapped in TLS
pathtofile/etwRunner
Basic KrabsETW runner template
pathtofile/terraform-provider-bitlaunch
BitLaunch Terraform Provider
pathtofile/etrace
strace-like logging using bpftrace and eBPF
pathtofile/etw_watcher
Using GitHub Actions to create commit diffs
pathtofile/hijack-watcher
Rust version of HijackWatcher
pathtofile/sgproxy
Basic HTTP/S proxy. Created to add HTTP Auth to a request from a client that doesn't support supplying auth in URL, for example VScode's Juypyter Notebook Server browser.
pathtofile/sigstore-watcher
Watches SigStore Code Signing Logs
pathtofile/aws-lambda-webrunner
pathtofile/Bandit-Scan
Use Bandit to scan all new and updated packages in Python
pathtofile/cargo-template
My own Cargo-Generate template
pathtofile/certstream-go
Go library for connecting to CertStream
pathtofile/crystal-face
Garmin Connect IQ watch face
pathtofile/dictpath
Provides a simple path-like access to nested dictionary elements
pathtofile/Docker-OSX
Run macOS VM in a Docker! Run near native OSX-KVM in Docker! X11 Forwarding! CI/CD for OS X Security Research! Docker mac Containers.
pathtofile/homebrew-toucli
Toucli Homebrew Tap
pathtofile/ios_configuration_profiles
This repo contains the parsed PList data from [Apple's Developer Configuration Profiles](https://developer.apple.com/bug-reporting/profiles-and-logs/?platform=ios).
pathtofile/json-log-exporter
Tails JSON log file and exports data in Prometheus format
pathtofile/KDU
Kernel Driver Utility
pathtofile/pathtofile
pathtofile profile repo
pathtofile/rustyshim
pathtofile/vscode-jupyter-remote-server
starts a private remote Jupyter notebook sever that you can connect to using VSCode's remote kernel mode