
DeTTECT
Detect Tactics, Techniques & Combat Threats
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Detect Tactics, Techniques & Combat Threats

Generates and maintains Azure Sentinel parser for Sysmon events, normalizing all Windows endpoint telemetry into a searchable log schema via…

A repository of my own Sigma detection rules.

A list of cyber-chef recipes and curated links

Analyze Windows Firewall outbound blocks and selectively allow traffic

Lightweight, secure control plane & real-time web dashboard in Crystal for Linux firewalld and NetworkManager host security.

Sigma rules from Joe Security

A post-processing script for TinyTracer

A repository to release detection rules to the public

A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon

A ProcessMonitor visualization application written in rust.

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

Some Threat Hunting queries useful for blue teamers

A curated list of awesome Security Hardening techniques for Windows.


Purpleteam scripts simulation & Detection - trigger events for SOC detections

A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).