Michael Haag

Elite
@MHaggis

sysmon-dfir. Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.

942

PowerShell-Hunter. PowerShell tools to help defenders hunt smarter, hunt harder.

486

hunt-detect-prevent. Lists of sources and utilities utilized to hunt, detect and prevent evildoers.

171

ClickGrab. Finding ClickFix and FakeCAPTCHA like it's 1999

151

notes. Full of public notes and Utilities

135

ASRGEN. ASR Configurator, Essentials and Atomic Testing

108

CBR-Queries. Collection of useful, up to date, Carbon Black Response Queries

87

MSIXBuilder. MSIX Building Made Easy for Defenders

64

ShellSweep. ShellSweeping the evil.

53

sysmon-splunk-app. Sysmon Splunk App

47

app_splunk_sysmon_hunter. Splunk App to assist Sysmon Threat Hunting

37

NPM-Threat-Emulation. Helping defenders learn and validate npm supply-chain detections with safe atomic tests.

34

bookish-happiness. OG Atomic Red Team

29

SDDLMaker. The home of the SDDLMaker

29

AppLockerGen. AppLocker Policy Generator

26

SequelEyes. SQL, IIS, Oh My...

23

HeapLeakDetection. C++

14

CBResponse-Splunk-Hunting. Analyzing Carbon Black Response endpoint telemetry in Splunk

6

Splunk_CBER_App. Splunk Carbon Black Enterprise Response App

6

atomic-red-team. Small and highly portable detection tests based on MITRE's ATT&CK.

5

sigZap. SigZap is a Streamlit application designed to facilitate the search across multiple network signature sets at once.

4

UltimateAppLockerByPassList. The goal of this repository is to document the most common techniques to bypass AppLocker.

3

pentest-wiki. PENTEST-WIKI is a free online security knowledge library for pentesters / researchers. If you have a good idea, please share it with others.

3

WinTrace. Run Windows Trace cmdline

2

Sysmon-Threat-Intel.

2

PELoader. Load PE via XML Attribute

2

KrbRelayUp. KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

2

MHaggis.

2

ModSecurity. ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analysis.

2

HackerArt. A collection of art inspired by the world of cybersecurity and hacking culture.

1

AppLockerInspector. Audits an AppLocker policy XML and reports weak/misconfigured/risky settings, including actual ACL checks.

1

BlackLotus. BlackLotus UEFI Windows Bootkit

1

subTee-gits-backups. subTee gists code backups

1

tomcat-jmxproxy-rce-exp. Apache Tomcat JMXProxy RCE

1

sigma. Generic Signature Format for SIEM Systems

1

amsi-tracer. Leverage AMSI (Antimalware Scan Interface) technology to aid your analysis. This tool saves all buffers (scripts, .NET assemblies, etc) passed into AMSI during dynamic execution.

1

LLM. LLM tools and toys

1

attack_range. A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk

1

webshells. Various webshells. We accept pull requests for additions to this collection.

1

Splunk_TA_bit9-carbonblack.

1
40
Apply