
EDR-Telemetry
This project aims to compare and evaluate the telemetry of various EDR products.
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

This project aims to compare and evaluate the telemetry of various EDR products.

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

MITRE ATT&CK mapped queries for SentinelOne Deep Visiblity

Awesome list of keywords and artifacts for Threat Hunting sessions

This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need…

Single-host runtime-security dashboard on eBPF — Go agent + SvelteKit. Live process tree, network map, and rule-based alerts for plain Linux hosts.

CVE-2023-38831 WinRAR lab: detection with Sysmon/Wazuh, reverse engineering with Ghidra, patch analysis, and remediation.

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…

MDE/MDI Defender setup for Ludus

TrustedSec Sysinternals Sysmon Community Guide

DECeption with Evaluative Integrated Validation Engine (DECEIVE): Let an LLM do all the hard honeypot work!

Sigma rules to share with the community

A repository hosting example goodware evtx logs containing sample software installation and basic user interaction

Provides curated Sysmon event-tracing configuration templates for detecting Cobalt Strike, webshells, ransomware artifacts, and known exploit…

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

GitHub mirror of the Linux Kernel's audit repository

CY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271