
Sentinel-Queries
Curated collection of Microsoft Sentinel KQL queries and tutorials for hunting threats, analyzing Azure AD sign-in logs, detecting anomalies, and…

Curated collection of Microsoft Sentinel KQL queries and tutorials for hunting threats, analyzing Azure AD sign-in logs, detecting anomalies, and…

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

Parses Windows .evtx logs to identify remote connections and public IPs by analyzing EventIDs related to remote logins and sessions.

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

Dshell is a network forensic analysis framework.

Post-Exploitation EVTX Analyzer for BloodHound Mapping

Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.


A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon

A collection of scripts which may come in handy during your freedom fighting activities.

A repository to release detection rules to the public