auditd-attack. A Linux Auditd rule set mapped to MITRE's Attack Framework
821ThreatHunter-Playbook. A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns.
14FuzzySysmon. My sysmon config I use for testing purposes
1Windows_Baselines. Windows Baselines
1Windows-Hunting.
1threat_hunting_tables. Theat hunting notes in flat file format and mapped to MITRE's ATT&CK IDs
1