
Detection-Rules
This repository contains validated detection rules for adversary behaviors observed during APT29 simulation. Each rule was tested against the actual…
curated-resourceseducationintrusion-detection+4
4

This repository contains validated detection rules for adversary behaviors observed during APT29 simulation. Each rule was tested against the actual…

Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows…