
cowrie
Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

💻🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.

Live monitoring tool for remote PowerShell sessions using ETW to capture and decode WinRM/PSRP protocol, providing command execution traces and…

Open-source security orchestration, automation, and response (SOAR) platform with a visual workflow editor, prebuilt security app integrations, and…

This repository has both an attack detection tool and a Proof-of-Concept (PoC) Python script for the WinRAR CVE-2023-38831 vulnerability.

Curated collection of EDR bypass resources including PoCs, tools, workshops, presentations, and blogs for ethical hacking and red team operations.

PowerShell tool for red teamers that clears execution evidence by stopping event logging, removing file and registry artifacts, and saving timestamps…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Tools and Techniques for Blue Team / Incident Response

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS…

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

Detect Tactics, Techniques & Combat Threats

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

Automatic security alert response framework by AWS Serverless Application Model

Powershell to mitigate CVE-2022-29072

A collection of awesome security hardening guides, tools and other resources