
cve-2025-24054-lab
Blue-team lab: detecting & mitigating CVE-2025-24054 (Windows NTLM hash disclosure) with Sysmon, Wazuh SIEM, and Group Policy
authenticationconfiguration-auditingeducation+7

Blue-team lab: detecting & mitigating CVE-2025-24054 (Windows NTLM hash disclosure) with Sysmon, Wazuh SIEM, and Group Policy

My attempt to make honeypot for React2Shell vulnerability (CVE-2025-66478)

Zeek script and Suricata rules to detect PrintNightmare (CVE-2021-1675) exploitation via RpcAddPrinterDriver DCE RPC events, with PCAP-based testing.

CVE-2020-16899 - Microsoft Windows TCP/IP Vulnerability Detection Logic and Rule