Threat Hunting & DFIR
EVTX-ATTACK-SAMPLES. Windows Events Attack Samples
2.6kSlides. Misc Threat Hunting Resources
376PCAP-ATTACK. PCAP Samples for Different Post Exploitation Techniques
375macOS-ATTACK-DATASET. JSON DataSet for macOS mapped to MITRE ATT&CK Tactics.
160YaraHunts. Random hunting ordiented yara rules
96injection-1. Windows process injection methods
21mail-security-tester. A testing framework for mail security and filtering solutions.
8shad0w. A post exploitation framework designed to operate covertly on heavily monitored enviroments
7APT_Digital_Weapon. Indicators of compromise (IOCs) collected from public resources and categorized by Qi-AnXin.
5malware-1. Malware source code samples leaked online uploaded to GitHub for those who want to analyze the code.
4evtx2es. Import Windows Eventlogs(.evtx) to ElasticSearch.
4APT_CyberCriminal_Campagin_Collections. APT & CyberCriminal Campaign Collection
3MalConfScan. Volatility plugin for extracts configuration data of known malware
3PythonForWindows. A codebase aimed to make interaction with Windows and native execution easier
3WindowsDefenderATP-Hunting-Queries. Sample queries for Advanced hunting in Microsoft Defender ATP
3Adama. Searches For Threat Hunting and Security Analytics
3auditd. Best Practice Auditd Configuration
2rules. Repository of yara rules
2OffensiveVBA. This repo covers some code execution and AV Evasion methods for Macros in Office documents
2Win10. Win 10 related research
2sysmonx. SysmonX - An Augmented Drop-In Replacement of Sysmon
2malware-ioc. Indicators of Compromises (IOC) of our various investigations
2Windows-Kernel-Explorer. A free but powerful Windows kernel research tool.
2UACME. Defeating Windows User Account Control
2APT_REPORT. Interesting apt report collection and some special ioc express
2Revoke-Obfuscation. PowerShell Obfuscation Detection Framework
1injection. C++
1webshell. This is a webshell open source project
1Rubeus. Trying to tame the three-headed dog.
1ioc-scanner-CVE-2019-19781. Indicator of Compromise Scanner for CVE-2019-19781
1PowerSploit. PowerSploit - A PowerShell Post-Exploitation Framework
1OneOffs. Small random scripts for various things I find myself needing to repeat/automate
1sandbox-attacksurface-analysis-tools. Set of tools to analyze and attack Windows sandboxes.
1unicorn. Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique presented by David Kennedy (TrustedSec) and Josh Kelly at Defcon 18.
1Sharp-SMBExec. SMBExec C# module
1AsyncRAT-C-Sharp. Open-Source Remote Administration Tool For Windows C# (RAT)
1sigma. Generic Signature Format for SIEM Systems
1HyperDbg. The Source Code of HyperDbg Debugger 🐞
1PowerMemory. Exploit the credentials present in files and memory
1PeFixup. PE File Blessing - To continue or not to continue
1detection-rules. Rules for Elastic Security's detection engine
1ExchangeLogCollector. Exchange Log Collection Script
1defcon_27_windbg_workshop. DEFCON 27 workshop - Modern Debugging with WinDbg Preview
1Windows-classic-samples. This repo contains samples that demonstrate the API used in Windows classic desktop applications.
1InfinityHook. Hook system calls, context switches, page faults and more.
1injectAllTheThings. Seven different DLL injection techniques in one single project.
1HastySeries. ObscurityLabs RedTeam C# Toolkit
1eqllib. Python
1VBA-RunPE. A VBA implementation of the RunPE technique or how to bypass application whitelisting.
1osq-ext-bin. Extension to osquery windows that enhances it with real-time telemetry, log monitoring and other endpoint data collection
1LinEnum. Scripted Local Linux Enumeration & Privilege Escalation Checks
1