This is your work, valued

The Netherlands

Olaf Hartong

Elite
@olafhartong

sysmon-modular. A repository of sysmon configuration modules

3.1k

ThreatHunting. A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

1.2k

sysmon-cheatsheet. All sysmon event types and their fields explained

570

ATTACKdatamap. A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework

357

BamboozlEDR. A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.

275

DefenderHarvester. Expose a lot of MDE telemetry that is not easily accessible in any searchable form

120

MDE-AuditCheck. MDE relies on some of the Audit settings to be enabled

101

Presentations. My conference presentations

86

ETWLocksmith. A powerful Windows command-line tool for analyzing and searching ETW (Event Tracing for Windows) provider permissions from the Windows registry.

72

PockETWatcher. a tiny program to consume from ETW providers for research

55

detection-sources.

53

BHCEupload. A small go tool to upload JSON files to the BloodHound community edition API

33

TA-Sysmon-deploy. Deploy and maintain Symon through the Splunk Deployment Sever

32

WDACme. A WDAC configuration repository with the sole intention of enriching MDE

30

sysmon-parser. Automatically generated Sysmon parser for Azure Sentinel

18

sysmon-modular-linux. A repository of Sysmon For Linux configuration modules

17

parsoalto. Palo Alto Networks Rule Parser

16

Sentinel-template-parser. Azure Sentinel Template parser

16

SA-Threat-Hunting. Splunk app for Threat hunting

15

PSSysmonTools. Sysmon Tools for PowerShell

12

Invoke-Phant0m. Windows Event Log Killer

11

ETWhat. ETWhat is a Windows utility that determines whether Event Tracing for Windows (ETW) providers operate in kernel mode or user mode.

10

unfetter-discover. Unfetter-Discover Vagrant script for the Unfetter-Discover docker release

8

osx-defaults. All my default config stuff for mac

8

DetectionLab. Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices

6

ETWtop. A real-time monitoring tool for Event Tracing for Windows (ETW) session buffers

6

scripts. just random simple scripts

5

SysmonCommunityGuide. TrustedSec Sysinternals Sysmon Community Guide

5

provmon. A specialized ETW (Event Tracing for Windows) monitoring tool that traces the Microsoft-Windows-Kernel-EventTracing provider for Event ID 8.

4

sysmon-dfir. Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.

3

blackhat-arsenal-tools. Official Black Hat Arsenal Security Tools Repository

3

olafhartong.

3

disposable-windows. A packer project to quickly have a test / dev / IR box

2

ETW-DBG-ENUM. Enumerates all ETW sessions from kernel structures

2

splunk-jupyter. Analyse your Splunk data from a Jupyter Notebook, as a Pandas Dataframe.

2

TA-microsoft-sysmon. TA-microsoft-sysmon

2

Event-Forwarding-Guidance. Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding. iadgov

2

subTee-gits-backups. subTee gists code backups

2

LOLDrivers. Living Off The Land Drivers

2

SplunkTools. A collection of scripts useful in management of Splunk deployment

1

SomeStuff. Some PowerShell Stuff

1

Azure-Sentinel. Cloud-native SIEM for intelligent security analytics for your entire enterprise.

1

sysmon-splunk-app. Sysmon Splunk App

1

flushwifi. a simple script written for OSX to restart all network interfaces, clear ARP cache, and flush routes. also includes MAC randomization and protection from ICMP redirect attacks.

1

ARTHIR. ATT&CK Remote Threat Hunting Incident Response

1

sigma. Generic Signature Format for SIEM Systems

1

OSSEM-DM. OSSEM Detection Model

1

raycast-extensions. Everything you need to extend Raycast.

1

RTA. Python

1

cti. Cyber Threat Intelligence Repository expressed in STIX 2.0

1

BloodHound. Six Degrees of Domain Admin

1