
Threat-Remediation-Scripts
This repository contains a list of new remediation scripts.
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

This repository contains a list of new remediation scripts.

Evtx Log (xml) Browser

A Simple Ransomware Vaccine


Curated collection of Microsoft Sentinel KQL queries and tutorials for hunting threats, analyzing Azure AD sign-in logs, detecting anomalies, and…


Powershell module for VMWare vSphere forensics

Converts Sigma detection rules into OpenSearch Lucene and PPL queries, including alerting Monitor Rules and correlation support for SIEM detection…

The Sigma command line interface based on pySigma

Hunts for potential malware downloads and suspicious domain calls via common Windows LOLBins using YARA rules and Nexthink telemetry modules.

Rules generated from our investigations.

Strelka Web UI for File Submission and Analysis

Rapidly Search and Hunt through Windows Forensic Artefacts

A script that helps you understand why your E-Mail ended up in Spam

Parses Apple Unified Logs to extract process, thread, activity, timestamp, and message metadata from logarchives or live macOS systems into JSONL/CSV…

A repository of sysmon configuration modules

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…