
SysmonSimulator
Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and…

Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and…

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS…

Live hunting of code injection techniques

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Collection of private Yara rules.

Provides curated Sysmon event-tracing configuration templates for detecting Cobalt Strike, webshells, ransomware artifacts, and known exploit…

A collection of companies that disclose adversary TTPs after they have been breached

A powerful and user-friendly browser extension that streamlines investigations for security professionals.

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

Volatility plugin for extracts configuration data of known malware

This repository contains a list of new remediation scripts.

Collecting & Hunting for IOCs with gusto and style

Detect and respond to Cobalt Strike beacons using ETW.

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

CredsHunter - Credential Hunting scripts for Windows and Linux OS

Build a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI