
printnightmare-detection-lab
Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…
adversarial-attackeducationexploitation+6

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

A Zeek based AsyncRAT malware detector.

A Zeek based NetSupport detector. NetSupport is often abused by attackers in malware.

A Zeek protocol analyzer for the Facefish rootkit, based on Spicy.

High fidelity defensive security lab simulating a DoD aligned enterprise network with Active Directory, VLAN segmentation, STIG based hardening,…