How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.
BloodHound is an identity risk management platform and graph-based attack path analyzer used to map identity relationships and permissions in Active Directory. It functions as a security tool for auditing directory services, uncovering unintended privilege relationships, and visualizing sequences of permissions that can lead to domain compromise. The project differentiates itself as a comprehensive adversary emulation framework that coordinates remote agents and executes post-exploitation commands. It includes a reverse proxy for bypassing multi-factor authentication via real-time session hij
Zphisher is a security testing framework designed for conducting authorized social engineering assessments and penetration testing. It functions as a credential harvesting simulator that enables security professionals to evaluate organizational defenses and user awareness by deploying deceptive login interfaces. The platform automates the creation of realistic web pages through dynamic template rendering and provides tools to mask destination addresses. It integrates reverse proxy tunneling to expose local testing services to the public internet, allowing for remote access during security aud
Viper is a command and control infrastructure manager and post-exploitation framework designed for adversary attack simulation and security assessment. It functions as an orchestrator for penetration testing, combining a system for managing compromised hosts across multiple operating systems with tools for security workflow automation. The platform is distinguished by its use of large language model agents to coordinate red team tasks, automate data processing, and provide intelligent decision support. It includes a network pivot visualizer that uses directional graphs to map relationships an
This project is a cryptography educational book and digital textbook that provides an introductory guide to cryptographic fundamentals, including block ciphers, hash functions, and public key encryption. It also serves as a cryptography lab manual for simulating security attacks, such as forging cookies and recovering passwords, to identify system vulnerabilities. The project utilizes a technical document rendering system to transform raw instructional text and source files into a professionally formatted digital book. This allows the content to be exported into multiple formats, specifically
The main features of cloud-architekt/azuread-attack-defense are: Security Mitigation Playbooks, MITRE ATT&CK Analysis, Attack Scenario Mappings, Identity Risk Mitigation, Identity Attack Detections, Microsoft Graph API Audits, Microsoft Security Stack Detections, Attack Simulations.
Open-source alternatives to cloud-architekt/azuread-attack-defense include: specterops/bloodhound — BloodHound is an identity risk management platform and graph-based attack path analyzer used to map identity… htr-tech/zphisher — Zphisher is a security testing framework designed for conducting authorized social engineering assessments and… crypto101/book — This project is a cryptography educational book and digital textbook that provides an introductory guide to… fireeye/capa — capa is a static analysis tool that scans executable files to identify what a program can do, detecting capabilities… funnywolf/viper — Viper is a command and control infrastructure manager and post-exploitation framework designed for adversary attack… guardicore/monkey — Monkey is an adversary emulation platform and breach and attack simulation tool designed to test network defenses…