
Analysis
Hands-on detection research repository documenting how APT techniques appear in logs, with practical detection logic, Splunk queries, and Sigma rules…
educationincident-responselog-analysis

Hands-on detection research repository documenting how APT techniques appear in logs, with practical detection logic, Splunk queries, and Sigma rules…

End-to-end cybersecurity project demonstrating detection and mitigation of CVE-2024-38063 using IDS, host-based monitoring, and virtual lab attack…

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

A python script developed to process Windows memory images based on triage type.

Kernel-mode filter driver that monitors ConDrv traffic to detect mimikatz execution in real-time, logging detection events via ETW for incident…