Mortar is an evasion technique designed to defeat and divert detection and prevention of security products, including Antivirus (AV), Endpoint Detection and Response (EDR), and Extended Detection and Response (XDR) solutions. It provides a framework for evading detection by security products, allowing for more effective penetration testing and red teaming exercises. Mortar's evasion techniques are designed to bypass security controls, enabling testers to identify vulnerabilities and weaknesses in an organization's defenses. The tool is intended for use by authorized security professionals and penetration testers, and should only be used with proper authorization and in accordance with applicable laws and regulations. By using Mortar, security professionals can simulate real-world attacks, identify vulnerabilities, and improve the overall security posture of an organization.
FEATURES
ALTERNATIVES
Utilizes dirtyc0w kernel exploit for privilege escalation in a Docker container.
A modular and script-friendly multithread bruteforcer for managing task parameters in Python scripts.
A collaborative, multi-platform, red teaming framework for simulating attacks and testing defenses.
A distributed systems and infrastructure simulator for attacking and debugging Kubernetes.
A guide on basic Linux privilege escalation techniques including enumeration, data analysis, exploit customization, and trial and error.
Python-based toolkit for network hacking with various implemented techniques and supported by Securetia SRL.
A C++ staged shellcode loader with evasion capabilities, compatible with Sliver and other shellcode sources, designed for offensive security testing.
PINNED

InfoSecHired
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.

Mandos Brief Newsletter
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

Kriptos
An AI-driven data classification and governance platform that automatically discovers, analyzes, and labels sensitive information while providing risk management and compliance capabilities.

System Two Security
An AI-powered platform that automates threat hunting and analysis by processing cyber threat intelligence and generating customized hunt packages for SOC teams.

Aikido Security
Aikido is an all-in-one security platform that combines multiple security scanning and management functions for cloud-native applications and infrastructure.

Permiso
Permiso is an Identity Threat Detection and Response platform that provides comprehensive visibility and protection for identities across multiple cloud environments.

Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.

Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.