
BruteRatel-DetectionTools
A collection of Tools and Rules for decoding Brute Ratel C4 badgers

A collection of Tools and Rules for decoding Brute Ratel C4 badgers


Corelight-Ansible-Roles are a collection of Ansible Roles and playbooks that install, configure, run and manage a variety of Corelight, Suricata and…

SQL powered operating system instrumentation, monitoring, and analytics.

A repository of sysmon configuration modules

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Collection of private Yara rules.

Provides curated Sysmon event-tracing configuration templates for detecting Cobalt Strike, webshells, ransomware artifacts, and known exploit…

Detect and log CVE-2019-19781 scan and exploitation attempts.

Detects attempts and successful exploitation of CVE-2022-26809

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

Detection of RCE in Oracle's WebLogic Server CVE-2020-14882 / CVE-2020-14750

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

Custom YARA rule for detecting artifacts of CVE-2025-32433, an Erlang/OTP SSH pre-authentication RCE vulnerability. Validated against public PoCs and…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Detection of Manjusaka C2 framework