EVTX-ETW-Resources. Event Tracing For Windows (ETW) Resources
433MindMaps. #ThreatHunting #DFIR #Malware #Detection Mind Maps
308SIGMA-Resources. Resources To Learn And Understand SIGMA Rules
188Misc-Research. A collection of tools, scripts and personal research
157C2-Matrix-Indicators. This repository aims to collect and document indicators from the different C2's listed in the C2-Matrix
74Eventlog_Compendium. The Eventlog Compendium is the go-to resource for understanding Windows Event Logs.
57SEDR-Internals. Symantec EDR Internals
32procmon-malware-analysis-filters. Repository containing malware analysis filters for the Windows SysInternals' - Process Monitor tool
21Multi-Threaded-BruteForcer. A script that automates a brute-force attack on a login page
13Awesome-Detection-Engineering. Resources and Discussions About Detection Engineering
12sigma. Generic Signature Format for SIEM Systems
10sedr-localdatastore-parser. Parser for Symantec EDR "localdatastore" folder
8Encoder-Decoder. A python script that contains multiple functionalities (Hashing, Encoding/Decoding...etc.)
6LOLDrivers. Living Off The Land Drivers
4DefenderYara. Extracted Yara rules from Windows Defender mpavbase and mpasbase
4Slides. A collection of my slides and presentations
4Ransomware-Tool-Matrix. A resource containing all the tools each ransomware gangs uses
3BigBountyRecon. BigBountyRecon tool utilises 58 different techniques using various Google dorks and open source tools to expedite the process of initial reconnaissance on the target organisation.
3LawEnforcementResources. Resources provided by the community that can serve to be useful for Law Enforcement worldwide
3awesome-event-ids. Collection of Event ID ressources useful for Digital Forensics and Incident Response
2DFIRPowerShellScripts. Various PowerShells scripts I've made to automate some of the boring stuff in my everyday DFIR journey!
2LOLRMM. LotL RMM
2winevt-kb. Windows Event Log Knowledge Base
2atomic-red-team. Small and highly portable detection tests based on MITRE's ATT&CK.
2sysmon-config. Sysmon configuration file template with default high-quality event tracing
2wil. Windows Implementation Library
2SysmonCommunityGuide. TrustedSec Sysinternals Sysmon Community Guide
2Zircolite. A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
2droid. A pySigma wrapper to manage detection rules.
2threathunters. YARA
2The_Shelf. Retired TrustedSec Capabilities
2detection-rules. Python
1NimPlant. A light-weight first-stage C2 implant written in Nim.
1LOLBAS. Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
1MAL-CL. MAL-CL (Malicious Command-Line)
1CVE-2019-19547. CVE-2019-19547 POC
1CVE-2020-12593. CVE-2020-12593 POC
1SIGMA-detection-rules. Set of SIGMA rules (>320) mapped to MITRE ATT&CK tactic and techniques
1VanillaWindowsReference. A repo that contains recursive dir listings of a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update.
1pySigma-backend-elasticsearch. pySigma Elasticsearch backend
1panopticon. A YARA Rule Performance Measurement Tool
1