Cyb3rMonk
Threat-Hunting-and-Detection. Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).
821RITA-J. Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.
214ACCD. Active C&C Detector
155Microsoft-Vulnerable-Driver-Block-Lists. Microsoft Vulnerable Driver Block Lists in CSV and JSON for SIEM lookups
55Cheat-Sheets. Cheat sheets for threat hunting, detection and other stuff.
34blue-teaming-with-kql. Repository with Sample KQL Query examples for Threat Hunting
11Spartacus. Spartacus DLL Hijacking Discovery Tool
5Real-CyberSecurity-Datasets. Public datasets to help you address various cyber security problems.
4blueteam_homelabs. Great List of Resources to Build an Enterprise Grade Home Lab
4azure-kql. Azure KQL (Kusto Query Language) tips, tricks and best practices for Threat Hunting, Blue Teaming, etc.
4socbed. A Self-Contained Open-Source Cyberattack Experimentation Testbed
3malware_training_vol1. Materials for Windows Malware Analysis training (volume 1)
3GHOSTS. GHOSTS is a realistic user simulation framework for cyber simulation, training, and exercise
2DefensiveSysmon. Repository for Defensive applications of Windows Sysmon
2Microsoft-M365D-Hunting-Queries. Sample queries for Advanced hunting in Microsoft Threat Protection
2SPEED-SIEM-Use-Case-Framework. Repository for SPEED SIEM Use Case Framework
2TokenFinder. Tool to extract powerful tokens from Office desktop apps memory
1pytune. Python
1defcon33_silence_kill_edr. C++
1OktaGinx.
1SharpTokenFinder. C# implementation of TokenFinder. Steal M365 access tokens from Office Desktop apps
1GraphAZAccess. Jupyter Notebook
1msticpy. Microsoft Threat Intelligence Security Tools
1CloudPentestCheatsheets. This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.
1TripleCross. A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.
1labs_modern_malware_c2. labs_modern_malware_c2 Originally supporting Defcon workshop, will morph into Attack Defend for C2.
1etw-event-dumper. C#
1bind9_logparse_stat. A simple frequency analysis script for bind9 DNS query logs. Is able to analyze based on client IP address, DNS domain name, and DNS query type. Uses both regular expressions, and the Counter() dictionary from the Python collections module. Is written to demonstrate how useful the combination of a Counter() dictionary and regular expressions are.
1alerting-detection-strategy-framework. A framework for developing alerting and detection strategies for incident response.
1ml-qrg. Machine Learning Quick Reference Guide
1hot-manchego. Macro-Enabled Excel File Generator (.xlsm) using the EPPlus Library.
1Blackout. kill anti-malware protected processes using BYOVD
1attack-flow. ATT&CK Flow helps executives, SOC managers, and defenders easily understand how attackers compose ATT&CK techniques into attacks by developing a representation of attack flows, modeling attack flows for a small corpus of incidents, and creating visualization tools to display attack flows.
1Ciphey. Automated decryption tool
1Cyb3rMonk. Whoami
1