
Azure-Sentinel
Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

Tools and Techniques for Blue Team / Incident Response

Attack and defend active directory using modern post exploitation adversary tradecraft activity

One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️

A huge blocklist of manually curated sites that contain AI generated imagery for uBlock Origin & uBlacklist.

Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats

This project aims to compare and evaluate the telemetry of various EDR products.

Curated collection of Microsoft Sentinel KQL queries and tutorials for hunting threats, analyzing Azure AD sign-in logs, detecting anomalies, and…

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

Curated collection of EDR bypass resources including PoCs, tools, workshops, presentations, and blogs for ethical hacking and red team operations.

Draw.io libraries for threat modeling diagrams

AV/EDR Lab environment setup references to help in Malware development

Rules generated from our investigations.

A repository that maps commonly used attacks using MSRPC protocols to ATT&CK

Repository of Yara Rules