Lists (11)
Sort Name ascending (A-Z)
CTI
Detection Engineering
DFIR
🔮 Future ideas
KQL
for micrsoft KQL detection and hunting👀malware analysis/development
Malware Sample
For interesting malware sample that I want to analyzePentest
Starred repositories
A curated collection of DFIR skills and workflows for InfoSec practitioners.
Logging Made Easy (LME) is a no cost, open source platform that centralizes log collection, enhances threat detection, and enables real-time alerting, helping small to medium-sized organizations se…
Notebooks & Example Apps for Search & AI Applications with Elasticsearch
Microsoft 365 Advanced Hunting Queries with hotlinks that plug the query right into your tenant.
KQL queries for Microsoft Defender Advanced Hunting organized around the TTPs of the MITRE ATT&CK framework.
The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behavior
Sublime rules for email attack detection, prevention, and threat hunting.
A starter pack of resources to help you get started in Detection Engineering.
End-to-end ransomware attack simulation logs for DFIR/SOC analysts
Ludus range for the Constructing Defense Lab
Microsoft Defender XDR threat hunting KQL queries
CrowdStrike Falcon Advanced Threat Hunting Queries
Model Context Protocol Servers
This is the report that goes with my mock full-scope red team engagement against Game of Active Directory.
This project is aimed at creating a fun Capture the Flag experience while testing your Kibana skills!
BC-SECURITY / Empire
Forked from EmpireProject/EmpireEmpire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.
CyberSecurity BLUE TEAM containerized platform that brings together open-source tools for SIEM, DFIR, CTI, SOAR, and Network Analysis
Collection of example YARA-L rules for use within Google Security Operations
Aggregated ATT&CK technique reporting data. Presented at Splunk GovSummit December 2022
A curated Cyber "Security Orchestration, Automation and Response (SOAR)" awesome list.
UraSecTeam / mordor
Forked from OTRF/Security-DatasetsRe-play Adversarial Techniques
A tool to assess data quality, built on top of the awesome OSSEM.