sysmon-modular. A repository of sysmon configuration modules
3.1kThreatHunting. A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
1.2ksysmon-cheatsheet. All sysmon event types and their fields explained
570ATTACKdatamap. A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework
357BamboozlEDR. A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.
275DefenderHarvester. Expose a lot of MDE telemetry that is not easily accessible in any searchable form
120MDE-AuditCheck. MDE relies on some of the Audit settings to be enabled
101Presentations. My conference presentations
86ETWLocksmith. A powerful Windows command-line tool for analyzing and searching ETW (Event Tracing for Windows) provider permissions from the Windows registry.
72PockETWatcher. a tiny program to consume from ETW providers for research
55detection-sources.
53BHCEupload. A small go tool to upload JSON files to the BloodHound community edition API
33TA-Sysmon-deploy. Deploy and maintain Symon through the Splunk Deployment Sever
32WDACme. A WDAC configuration repository with the sole intention of enriching MDE
30sysmon-parser. Automatically generated Sysmon parser for Azure Sentinel
18sysmon-modular-linux. A repository of Sysmon For Linux configuration modules
17parsoalto. Palo Alto Networks Rule Parser
16Sentinel-template-parser. Azure Sentinel Template parser
16SA-Threat-Hunting. Splunk app for Threat hunting
15PSSysmonTools. Sysmon Tools for PowerShell
12Invoke-Phant0m. Windows Event Log Killer
11ETWhat. ETWhat is a Windows utility that determines whether Event Tracing for Windows (ETW) providers operate in kernel mode or user mode.
10unfetter-discover. Unfetter-Discover Vagrant script for the Unfetter-Discover docker release
8osx-defaults. All my default config stuff for mac
8DetectionLab. Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices
6ETWtop. A real-time monitoring tool for Event Tracing for Windows (ETW) session buffers
6scripts. just random simple scripts
5SysmonCommunityGuide. TrustedSec Sysinternals Sysmon Community Guide
5provmon. A specialized ETW (Event Tracing for Windows) monitoring tool that traces the Microsoft-Windows-Kernel-EventTracing provider for Event ID 8.
4sysmon-dfir. Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.
3blackhat-arsenal-tools. Official Black Hat Arsenal Security Tools Repository
3olafhartong.
3disposable-windows. A packer project to quickly have a test / dev / IR box
2ETW-DBG-ENUM. Enumerates all ETW sessions from kernel structures
2splunk-jupyter. Analyse your Splunk data from a Jupyter Notebook, as a Pandas Dataframe.
2TA-microsoft-sysmon. TA-microsoft-sysmon
2Event-Forwarding-Guidance. Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding. iadgov
2subTee-gits-backups. subTee gists code backups
2LOLDrivers. Living Off The Land Drivers
2SplunkTools. A collection of scripts useful in management of Splunk deployment
1SomeStuff. Some PowerShell Stuff
1Azure-Sentinel. Cloud-native SIEM for intelligent security analytics for your entire enterprise.
1sysmon-splunk-app. Sysmon Splunk App
1flushwifi. a simple script written for OSX to restart all network interfaces, clear ARP cache, and flush routes. also includes MAC randomization and protection from ICMP redirect attacks.
1ARTHIR. ATT&CK Remote Threat Hunting Incident Response
1sigma. Generic Signature Format for SIEM Systems
1OSSEM-DM. OSSEM Detection Model
1raycast-extensions. Everything you need to extend Raycast.
1RTA. Python
1cti. Cyber Threat Intelligence Repository expressed in STIX 2.0
1BloodHound. Six Degrees of Domain Admin
1