All mentioned security tools can be found here:


Windows RID Hijacking persistence technique
RID-Hijacking

Deserialization payload generator for a variety of .NET formatters
ysoserial.net

A targeted password brute force tool
PassGen

Auditing, system hardening, compliance testing
Lynis

A bunch of JavaScript extensions for WinDbg
windbg-scripts

A library for prototyping realtime hand detection (bounding box), directly in the browser
handtrack.js

BinDiff 5 for IDA 7.2. Windows. Linux. macOS
BinDiff

Six Degrees of Domain Admin - Update
BloodHound

A Bring Your Own Land Toolkit that Doubles as a WMI Provider
WheresMyImplant

Security auditing tool for Azure environments
azucar

Talks & Knowledge

XXE on Windows system …then what ??
XXE on Windows system

A software reverse engineering (SRE) suite of tools developed by NSA’s Research Directorate in support of the Cybersecurity mission
Ghidra Wiki


Ghidra from XXE to RCE
Ghidra from XXE to RCE