Netherlands

Mehmet E.

Elite
@Cyb3r-Monk

Cyb3rMonk

Threat-Hunting-and-Detection. Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).

821

RITA-J. Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

214

ACCD. Active C&C Detector

155

Microsoft-Vulnerable-Driver-Block-Lists. Microsoft Vulnerable Driver Block Lists in CSV and JSON for SIEM lookups

55

Cheat-Sheets. Cheat sheets for threat hunting, detection and other stuff.

34

blue-teaming-with-kql. Repository with Sample KQL Query examples for Threat Hunting

11

Spartacus. Spartacus DLL Hijacking Discovery Tool

5

Real-CyberSecurity-Datasets. Public datasets to help you address various cyber security problems.

4

blueteam_homelabs. Great List of Resources to Build an Enterprise Grade Home Lab

4

azure-kql. Azure KQL (Kusto Query Language) tips, tricks and best practices for Threat Hunting, Blue Teaming, etc.

4

socbed. A Self-Contained Open-Source Cyberattack Experimentation Testbed

3

malware_training_vol1. Materials for Windows Malware Analysis training (volume 1)

3

GHOSTS. GHOSTS is a realistic user simulation framework for cyber simulation, training, and exercise

2

DefensiveSysmon. Repository for Defensive applications of Windows Sysmon

2

Microsoft-M365D-Hunting-Queries. Sample queries for Advanced hunting in Microsoft Threat Protection

2

SPEED-SIEM-Use-Case-Framework. Repository for SPEED SIEM Use Case Framework

2

TokenFinder. Tool to extract powerful tokens from Office desktop apps memory

1

pytune. Python

1

defcon33_silence_kill_edr. C++

1

OktaGinx.

1

SharpTokenFinder. C# implementation of TokenFinder. Steal M365 access tokens from Office Desktop apps

1

GraphAZAccess. Jupyter Notebook

1

msticpy. Microsoft Threat Intelligence Security Tools

1

CloudPentestCheatsheets. This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.

1

TripleCross. A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.

1

labs_modern_malware_c2. labs_modern_malware_c2 Originally supporting Defcon workshop, will morph into Attack Defend for C2.

1

etw-event-dumper. C#

1

bind9_logparse_stat. A simple frequency analysis script for bind9 DNS query logs. Is able to analyze based on client IP address, DNS domain name, and DNS query type. Uses both regular expressions, and the Counter() dictionary from the Python collections module. Is written to demonstrate how useful the combination of a Counter() dictionary and regular expressions are.

1

alerting-detection-strategy-framework. A framework for developing alerting and detection strategies for incident response.

1

ml-qrg. Machine Learning Quick Reference Guide

1

hot-manchego. Macro-Enabled Excel File Generator (.xlsm) using the EPPlus Library.

1

Blackout. kill anti-malware protected processes using BYOVD

1

attack-flow. ATT&CK Flow helps executives, SOC managers, and defenders easily understand how attackers compose ATT&CK techniques into attacks by developing a representation of attack flows, modeling attack flows for a small corpus of incidents, and creating visualization tools to display attack flows.

1

Ciphey. Automated decryption tool

1

Cyb3rMonk. Whoami

1
35
Apply