This is your work, valued

sbousseaden

Elite
@sbousseaden

Threat Hunting & DFIR

EVTX-ATTACK-SAMPLES. Windows Events Attack Samples

2.6k

Slides. Misc Threat Hunting Resources

376

PCAP-ATTACK. PCAP Samples for Different Post Exploitation Techniques

375

macOS-ATTACK-DATASET. JSON DataSet for macOS mapped to MITRE ATT&CK Tactics.

160

YaraHunts. Random hunting ordiented yara rules

96

injection-1. Windows process injection methods

21

mail-security-tester. A testing framework for mail security and filtering solutions.

8

shad0w. A post exploitation framework designed to operate covertly on heavily monitored enviroments

7

APT_Digital_Weapon. Indicators of compromise (IOCs) collected from public resources and categorized by Qi-AnXin.

5

malware-1. Malware source code samples leaked online uploaded to GitHub for those who want to analyze the code.

4

evtx2es. Import Windows Eventlogs(.evtx) to ElasticSearch.

4

APT_CyberCriminal_Campagin_Collections. APT & CyberCriminal Campaign Collection

3

MalConfScan. Volatility plugin for extracts configuration data of known malware

3

PythonForWindows. A codebase aimed to make interaction with Windows and native execution easier

3

WindowsDefenderATP-Hunting-Queries. Sample queries for Advanced hunting in Microsoft Defender ATP

3

Adama. Searches For Threat Hunting and Security Analytics

3

auditd. Best Practice Auditd Configuration

2

rules. Repository of yara rules

2

OffensiveVBA. This repo covers some code execution and AV Evasion methods for Macros in Office documents

2

Win10. Win 10 related research

2

sysmonx. SysmonX - An Augmented Drop-In Replacement of Sysmon

2

malware-ioc. Indicators of Compromises (IOC) of our various investigations

2

Windows-Kernel-Explorer. A free but powerful Windows kernel research tool.

2

UACME. Defeating Windows User Account Control

2

APT_REPORT. Interesting apt report collection and some special ioc express

2

Revoke-Obfuscation. PowerShell Obfuscation Detection Framework

1

injection. C++

1

webshell. This is a webshell open source project

1

Rubeus. Trying to tame the three-headed dog.

1

ioc-scanner-CVE-2019-19781. Indicator of Compromise Scanner for CVE-2019-19781

1

PowerSploit. PowerSploit - A PowerShell Post-Exploitation Framework

1

OneOffs. Small random scripts for various things I find myself needing to repeat/automate

1

sandbox-attacksurface-analysis-tools. Set of tools to analyze and attack Windows sandboxes.

1

unicorn. Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique presented by David Kennedy (TrustedSec) and Josh Kelly at Defcon 18.

1

Sharp-SMBExec. SMBExec C# module

1

AsyncRAT-C-Sharp. Open-Source Remote Administration Tool For Windows C# (RAT)

1

sigma. Generic Signature Format for SIEM Systems

1

HyperDbg. The Source Code of HyperDbg Debugger 🐞

1

PowerMemory. Exploit the credentials present in files and memory

1

PeFixup. PE File Blessing - To continue or not to continue

1

detection-rules. Rules for Elastic Security's detection engine

1

ExchangeLogCollector. Exchange Log Collection Script

1

defcon_27_windbg_workshop. DEFCON 27 workshop - Modern Debugging with WinDbg Preview

1

Windows-classic-samples. This repo contains samples that demonstrate the API used in Windows classic desktop applications.

1

InfinityHook. Hook system calls, context switches, page faults and more.

1

injectAllTheThings. Seven different DLL injection techniques in one single project.

1

HastySeries. ObscurityLabs RedTeam C# Toolkit

1

eqllib. Python

1

VBA-RunPE. A VBA implementation of the RunPE technique or how to bypass application whitelisting.

1

osq-ext-bin. Extension to osquery windows that enhances it with real-time telemetry, log monitoring and other endpoint data collection

1

LinEnum. Scripted Local Linux Enumeration & Privilege Escalation Checks

1