
macos-collector
macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

Curated collection of Microsoft Sentinel KQL queries and tutorials for hunting threats, analyzing Azure AD sign-in logs, detecting anomalies, and…

A curated collection of DFIR skills and workflows for InfoSec practitioners.

A collection of scripts which may come in handy during your freedom fighting activities.

A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon

Curated collection of threat hunting and detection queries for CrowdStrike Falcon (CQL) and Microsoft Defender XDR (KQL), mapped to MITRE ATT&CK…

A Software as a Service (SaaS) log collection framework.

Searches For Threat Hunting and Security Analytics

A repository to release detection rules to the public

Sigma Rule for CVE-2025-49666


Incident Response collection and processing scripts with automated reporting scripts

A repository of sysmon configuration modules

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of…

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

This repository contains a list of new remediation scripts.