This is your work, valued
Venator. [⛔️ Deprecated] Venator is a python tool used to gather data for proactive detection of malicious activity on macOS devices.
★ 175Venator-Swift. Swift Command line tool used for proactive detection of malicious activity on macOS systems.
★ 68Bro-Scripts. A series of Bro Scripts created for detection purposes.
★ 19Jumper. Jumper is a script that parses Jump List artifacts and maps AppIDs to their corresponding application. (Windows)
★ 3Presentations-Publications. Repo of my public Presentations/Publications
★ 3ThreatHunter-Playbook. A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns.
★ 1fastbook. The fastai book, published as Jupyter Notebooks
★ 25ksecretive. Protect your SSH keys with your Mac's Secure Enclave
★ 8.7kprowler. Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
★ 14kGuideToMastodon. An increasingly less-brief guide to Mastodon
★ 919esfriend. A minimal malware analysis sandbox for macOS
★ 35zui. Zui is a powerful desktop application for exploring and working with data. The official front-end to the Zed lake.
★ 2kstenographer. Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets. Discussion/announcements at stenographer@googlegroups.com
★ 1.8kpics. File formats dissections and more...
★ 11kpe_tree. Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro and Rekall to dump in-memory PE files and reconstruct imports.
★ 1.3kdetection-rules. Python
★ 2.7kdocker-elk. The Elastic stack (ELK) powered by Docker and Compose.
★ 18kBeat-the-Machine. Reverse engineering basics in puzzle form
★ 185cyberchef-recipes. A list of cyber-chef recipes and curated links
★ 2.2kscala-style-guide. Databricks Scala Coding Style Guide
★ 2.8kdevrel. This repository contains the notebooks and presentations we use for our Databricks Tech Talks
★ 734JustEnoughScalaForSpark. A tutorial on the most important features and idioms of Scala that you need to use Spark's Scala APIs.
★ 672sinter. A user-mode application authorization system for MacOS written in Swift
★ 299ASM-Course. Assembly
★ 25gcp-iam-sentinel-examples. HCL
★ 28gcploit. These are tools we released with our 2020 defcon/blackhat talk https://www.youtube.com/watch?v=Ml09R38jpok
★ 174teslamate. A self-hosted data logger for your Tesla 🚘 [main maintainer=@JakobLichterfeld]
★ 8.8kProcMon-for-Linux. A Linux version of the Procmon Sysinternals tool
★ 4.7kflare-floss. FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.
★ 4.1kcapa. The FLARE team's open-source tool to identify capabilities in executable files.
★ 6.1kbulk_extractor. This is the development tree. Production downloads are at:
★ 1.4kMemProcFS. MemProcFS
★ 4.3kBLUESPAWN. An Active Defense and EDR software to empower Blue Teams
★ 1.3kSplunk-ETW. A Splunk Technology Add-on to forward filtered ETW events.
★ 31SwiftBelt. A macOS enumeration tool inspired by harmjoy's Windows-based Seatbelt enumeration tool. Author: Cedric Owens
★ 347macOSTools. macOS Offensive Tools
★ 271hollows_hunter. Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
★ 2.4kclass-dump. Generate Objective-C headers from Mach-O files.
★ 3.6kattack-arsenal. A collection of red team and adversary emulation resources developed and released by MITRE.
★ 539Post-Reformat. A guide to setting up Windows and MacOS the way I like it
★ 22MBE. Course materials for Modern Binary Exploitation by RPISEC
★ 6kDefenderCheck. Identifies the bytes that Microsoft Defender flags on.
★ 2.6kMarvel-Lab. A collection of Powershell scripts that will help automate the build process for a Marvel domain.
★ 153dangerzone. Take potentially dangerous PDFs, office documents, or images and convert them to safe PDFs
★ 5.6kdefcon27_csharp_workshop. Writing custom backdoor payloads with C# - Defcon 27 Workshop
★ 1.2kPcaps.
★ 59OSSEM. Open Source Security Events Metadata (OSSEM)
★ 3DidierStevensSuite. Please no pull requests for this repository. Thanks!
★ 2.5ksRDI. Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode
★ 2.5kOffensiveCSharp. Collection of Offensive C# Tooling
★ 1.5klearn_gnuawk. Example based guide to mastering GNU awk
★ 1.1kysoserial.net. Deserialization payload generator for a variety of .NET formatters
★ 3.8kpivpn. The Simplest VPN installer, designed for Raspberry Pi
★ 8kWindowsEventLogMetadata. Event metadata collected across all manifest-based ETW providers on Window 10 1903
★ 32Crescendo. Crescendo is a swift based, real time event viewer for macOS. It utilizes Apple's Endpoint Security Framework.
★ 1.1kAzure-Sentinel. Cloud-native SIEM for intelligent security analytics for your entire enterprise.
★ 6kImport-Marvel. Powershell script and CSV file that allows you to import marvel characters into Active Directory
★ 9alerter. Send User Alert Notification on MacOS from the command-line.
★ 1.2ksandbox-attacksurface-analysis-tools. Set of tools to analyze Windows sandboxes for exposed attack surface.
★ 2.3ketl2pcapng. Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.
★ 47bro-sysmon. How to Zeek Sysmon Logs!
★ 102fzf. :cherry_blossom: A command-line fuzzy finder
★ 82kattack_range. A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk
★ 2.5kKQL. Kusto Query Language
★ 417PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF
★ 80kMythic. A collaborative, multi-platform, red teaming framework
★ 4.7kMacShellSwift. Proof of concept MacOS post exploitation tool written in Swift. Designed as a POC for blue teams to build macOS detections. Author: Cedric Owens
★ 124ossem-power-up. A tool to assess data quality, built on top of the awesome OSSEM.
★ 79sigma. Main Sigma Rule Repository
★ 11kgrapl. Graph platform for Detection and Response
★ 698Windows-API-To-Sysmon-Events. A repository that maps API calls to Sysmon Event ID's.
★ 122goesf. Golang command line tool for the macOS Endpoint Security Framework
★ 29msticpy. Microsoft Threat Intelligence Security Tools
★ 2kdocs. documentations, slides decks...
★ 832siofra. Assembly
★ 511ProcessMonitor. Process Monitor Library (based on Apple's new Endpoint Security Framework)
★ 503WinTools. A collection of free miscellaneous Windows tools
★ 144EVTX-ATTACK-SAMPLES. Windows Events Attack Samples
★ 2.6kMicrosoft-365-Defender-Hunting-Queries. Sample queries for Advanced hunting in Microsoft 365 Defender
★ 2.1kdocker-stacks. Ready-to-run Docker images containing Jupyter applications
★ 8.4kLIEF. LIEF - Library to Instrument Executable Formats (C++, Python, Rust)
★ 5.5kEndpointSecurity. A module to expose the Endpoint Security library to Swift
★ 20sysmon-cheatsheet. All sysmon event types and their fields explained
★ 570Malcolm. Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
★ 2.5kScoutSuite. Multi-Cloud Security Auditing Tool
★ 7.8kCRuntimeFunctionHooker. An example of hooking C functions at runtime
★ 71threadexec. A library to execute code in the context of other processes on iOS 11.
★ 82swift-package-manager. The Package Manager for the Swift Programming Language
★ 10kSet-AuditRule. Useful access control entries (ACE) on system access control list (SACL) of securable objects to find potential adversarial activity
★ 96ParseZeekLogs. Utility for parsing Bro log files into CSV or JSON format
★ 42Security-Datasets. Re-play Security Events
★ 1.8kdarwin-xnu. Legacy mirror of Darwin Kernel. Replaced by https://github.com/apple-oss-distributions/xnu
★ 11kKapeFiles. This repository serves as a place for community created Targets and Modules for use with KAPE.
★ 861Awesome-Red-Teaming. List of Awesome Red Teaming Resources
★ 8ktoken-priv. Token Privilege Research
★ 885osx-re-101. A collection of resources for OSX/iOS reverse engineering.
★ 1.7kSharpSploit. SharpSploit is a .NET post-exploitation library written in C#
★ 1.9kSeatbelt. Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
★ 4.6kzeek-osquery. Bro/Zeek integration with osquery
★ 94xnumon. monitor macOS for malicious activity
★ 236OSSEM. Open Source Security Events Metadata (OSSEM)
★ 1.3kosquery. SQL powered operating system instrumentation, monitoring, and analytics.
★ 23kosquery-extensions. osquery extensions by Trail of Bits
★ 273attack-navigator. Web app that provides basic navigation and annotation of ATT&CK matrices
★ 2.4kmacOS-Security-and-Privacy-Guide. Community guide to securing and improving privacy on macOS.
★ 22kHELK. The Hunting ELK
★ 3.9kRTA. Python
★ 1.1kAPTSimulator. A toolset to make a system look as if it was the victim of an APT attack
★ 2.8kPowerKrabsEtw. PowerKrabsEtw is a PowerShell interface for doing real-time ETW tracing.
★ 102DetectionLab. Automate the creation of a lab environment complete with security tooling and logging best practices
★ 5katomic-red-team. Small and highly portable detection tests based on MITRE's ATT&CK.
★ 12kACE. Automated, Collection, and Enrichment Platform
★ 325PSReflect-Functions. Module to provide PowerShell functions that abstract Win32 API functions
★ 253LuLu. LuLu is the free open-source macOS firewall
★ 13kRATDecoders. Python Decoders for Common Remote Access Trojans
★ 1.1k