
Sigma-Rules
Rules generated from our investigations.

Rules generated from our investigations.

The Github project for The Defender's Guide by Luke Paine and Jonathan Johnson

Small tool to play with IOCs caused by Imageload events

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…

Runs custom filters on Elasticsearch and alerts on matches

Generate bulk YARA rules from YAML input

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

🔒 Spring4Shell Firewall Defense — Cybersecurity Incident Simulation This project is part of a Cybersecurity Job Simulation I completed in August…

Vulnerability Detection and Mitigation Apache ActiveMQ | Security Architectures and Systems Administration - on - Apache ActiveMQ Deserialization…

This repository contains an academic and technical analysis of CVE-2023-34362, a critical SQL injection vulnerability affecting the MOVEit Transfer…

Detailed analysis of the 2023 MOVEit Transfer data breach (CVE-2023-34362) for CS50 Cybersecurity. This project explores the technical impact of…

CVE-2023-38646

Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).

