
sublime-rules
Open-source YAML rule set for detecting and preventing email attacks including BEC, credential phishing, malware, and supporting threat hunting.

Open-source YAML rule set for detecting and preventing email attacks including BEC, credential phishing, malware, and supporting threat hunting.

MDE relies on some of the Audit settings to be enabled

A repository of sysmon configuration modules

Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool

TAXII server implementation in Python from EclecticIQ

Corelight Dashboards and Parsers for Sentinel One Singularity

PacketFence is a fully supported, trusted, Free and Open Source network access control (NAC) solution. Boasting an impressive feature set including a…

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

Set of tools to analyze Windows sandboxes for exposed attack surface.

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

The remediation script should set the reg entries described in https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884 . The detection…

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

Best Practice Auditd Configuration

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

A Linux Auditd rule set mapped to MITRE's Attack Framework

GitHub App to set and enforce security policies

Tools and technical write-ups describing attacking techniques that rely on concealing code execution on Windows

Windows tool to list, get, set, protect, and unprotect process protection levels (PP/L) for debugging, inspection, and privilege escalation.