This is your work, valued

HAL

Nasreddine Bencherchali

Elite
@nasbench

Wanna be detection engineer

EVTX-ETW-Resources. Event Tracing For Windows (ETW) Resources

433

MindMaps. #ThreatHunting #DFIR #Malware #Detection Mind Maps

308

SIGMA-Resources. Resources To Learn And Understand SIGMA Rules

188

Misc-Research. A collection of tools, scripts and personal research

157

C2-Matrix-Indicators. This repository aims to collect and document indicators from the different C2's listed in the C2-Matrix

74

Eventlog_Compendium. The Eventlog Compendium is the go-to resource for understanding Windows Event Logs.

57

SEDR-Internals. Symantec EDR Internals

32

procmon-malware-analysis-filters. Repository containing malware analysis filters for the Windows SysInternals' - Process Monitor tool

21

Multi-Threaded-BruteForcer. A script that automates a brute-force attack on a login page

13

Awesome-Detection-Engineering. Resources and Discussions About Detection Engineering

12

sigma. Generic Signature Format for SIEM Systems

10

sedr-localdatastore-parser. Parser for Symantec EDR "localdatastore" folder

8

Encoder-Decoder. A python script that contains multiple functionalities (Hashing, Encoding/Decoding...etc.)

6

LOLDrivers. Living Off The Land Drivers

4

DefenderYara. Extracted Yara rules from Windows Defender mpavbase and mpasbase

4

Slides. A collection of my slides and presentations

4

Ransomware-Tool-Matrix. A resource containing all the tools each ransomware gangs uses

3

BigBountyRecon. BigBountyRecon tool utilises 58 different techniques using various Google dorks and open source tools to expedite the process of initial reconnaissance on the target organisation.

3

LawEnforcementResources. Resources provided by the community that can serve to be useful for Law Enforcement worldwide

3

awesome-event-ids. Collection of Event ID ressources useful for Digital Forensics and Incident Response

2

DFIRPowerShellScripts. Various PowerShells scripts I've made to automate some of the boring stuff in my everyday DFIR journey!

2

LOLRMM. LotL RMM

2

winevt-kb. Windows Event Log Knowledge Base

2

atomic-red-team. Small and highly portable detection tests based on MITRE's ATT&CK.

2

sysmon-config. Sysmon configuration file template with default high-quality event tracing

2

wil. Windows Implementation Library

2

SysmonCommunityGuide. TrustedSec Sysinternals Sysmon Community Guide

2

Zircolite. A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

2

droid. A pySigma wrapper to manage detection rules.

2

threathunters. YARA

2

The_Shelf. Retired TrustedSec Capabilities

2

detection-rules. Python

1

NimPlant. A light-weight first-stage C2 implant written in Nim.

1

LOLBAS. Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

1

MAL-CL. MAL-CL (Malicious Command-Line)

1

CVE-2019-19547. CVE-2019-19547​ POC

1

CVE-2020-12593. CVE-2020-12593 POC

1

SIGMA-detection-rules. Set of SIGMA rules (>320) mapped to MITRE ATT&CK tactic and techniques

1

VanillaWindowsReference. A repo that contains recursive dir listings of a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update.

1

pySigma-backend-elasticsearch. pySigma Elasticsearch backend

1

panopticon. A YARA Rule Performance Measurement Tool

1