
Threat-Remediation-Scripts
This repository contains a list of new remediation scripts.

This repository contains a list of new remediation scripts.

Curated collection of Microsoft Sentinel KQL queries and tutorials for hunting threats, analyzing Azure AD sign-in logs, detecting anomalies, and…

A repository of sysmon configuration modules

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Detect Tactics, Techniques & Combat Threats

A repository to release detection rules to the public

A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon

Provides curated Sysmon event-tracing configuration templates for detecting Cobalt Strike, webshells, ransomware artifacts, and known exploit…

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Basic log analysis tool to detect impossible travel via IP address geographic information

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

Runs custom filters on Elasticsearch and alerts on matches

This repository contains Velociraptor artifact and Chainsaw rules to help detect Microsoft Remote Access VPN activity

A Simple Log4j Indicator of Compromise Linux Detector

Detection of Manjusaka C2 framework

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".
