sysmon-dfir. Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.
942PowerShell-Hunter. PowerShell tools to help defenders hunt smarter, hunt harder.
486hunt-detect-prevent. Lists of sources and utilities utilized to hunt, detect and prevent evildoers.
171ClickGrab. Finding ClickFix and FakeCAPTCHA like it's 1999
151notes. Full of public notes and Utilities
135ASRGEN. ASR Configurator, Essentials and Atomic Testing
108CBR-Queries. Collection of useful, up to date, Carbon Black Response Queries
87MSIXBuilder. MSIX Building Made Easy for Defenders
64ShellSweep. ShellSweeping the evil.
53sysmon-splunk-app. Sysmon Splunk App
47app_splunk_sysmon_hunter. Splunk App to assist Sysmon Threat Hunting
37NPM-Threat-Emulation. Helping defenders learn and validate npm supply-chain detections with safe atomic tests.
34bookish-happiness. OG Atomic Red Team
29SDDLMaker. The home of the SDDLMaker
29AppLockerGen. AppLocker Policy Generator
26SequelEyes. SQL, IIS, Oh My...
23HeapLeakDetection. C++
14CBResponse-Splunk-Hunting. Analyzing Carbon Black Response endpoint telemetry in Splunk
6Splunk_CBER_App. Splunk Carbon Black Enterprise Response App
6atomic-red-team. Small and highly portable detection tests based on MITRE's ATT&CK.
5sigZap. SigZap is a Streamlit application designed to facilitate the search across multiple network signature sets at once.
4UltimateAppLockerByPassList. The goal of this repository is to document the most common techniques to bypass AppLocker.
3pentest-wiki. PENTEST-WIKI is a free online security knowledge library for pentesters / researchers. If you have a good idea, please share it with others.
3WinTrace. Run Windows Trace cmdline
2Sysmon-Threat-Intel.
2PELoader. Load PE via XML Attribute
2KrbRelayUp. KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).
2MHaggis.
2ModSecurity. ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analysis.
2HackerArt. A collection of art inspired by the world of cybersecurity and hacking culture.
1AppLockerInspector. Audits an AppLocker policy XML and reports weak/misconfigured/risky settings, including actual ACL checks.
1BlackLotus. BlackLotus UEFI Windows Bootkit
1subTee-gits-backups. subTee gists code backups
1tomcat-jmxproxy-rce-exp. Apache Tomcat JMXProxy RCE
1sigma. Generic Signature Format for SIEM Systems
1amsi-tracer. Leverage AMSI (Antimalware Scan Interface) technology to aid your analysis. This tool saves all buffers (scripts, .NET assemblies, etc) passed into AMSI during dynamic execution.
1LLM. LLM tools and toys
1attack_range. A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk
1webshells. Various webshells. We accept pull requests for additions to this collection.
1Splunk_TA_bit9-carbonblack.
1