0x4D31 / honeybits-winLinks
Windows version of honeybits - a PoC tool to create breadcrumbs and honeytokens, to lead the attackers to your honeypots!
☆24Updated 8 years ago
Alternatives and similar repositories for honeybits-win
Users that are interested in honeybits-win are comparing it to the libraries listed below
Sorting:
- A few scripts I put together for testing purposes and to automate a few capabilities while doing IR. These scripts are also part of my bl…☆55Updated 7 years ago
- Security Onion Elastic Stack☆46Updated 4 years ago
- Mitre Att&ck Technique Emulation☆82Updated 6 years ago
- Threat hunting repo for my independent study on threat hunting with OSQuery☆27Updated 7 years ago
- A MITRE Caldera plugin written in Python 3 used to convert Red Canary Atomic Red Team Tests to MITRE Caldera Stockpile YAML ability files…☆72Updated 3 years ago
- ☆76Updated 7 years ago
- evtx2json extracts events of interest from event logs, dedups them, and exports them to json.☆42Updated 4 years ago
- THOR MITRE ATT&CK Framework Coverage☆24Updated 5 years ago
- Yara-Endpoint is a tool useful for incident response as well as anti-malware enpoint base on Yara signatures.☆109Updated 7 years ago
- A curated list of tools, papers and techniques for Windows exploitation and incident response.☆40Updated 9 years ago
- Python parser for Red Canary's Atomic Red Team Yamls☆27Updated 6 years ago
- Powershell collection designed to assist in Threat Hunting Windows systems.☆27Updated 7 years ago
- Sandbox feature upgrade with the help of wrapped samples☆76Updated 7 years ago
- Simulating Adversary Operations☆93Updated 7 years ago
- Build your own threat hunting maturity model☆11Updated 7 years ago
- A tool to assess data quality, built on top of the awesome OSSEM.☆78Updated 2 years ago
- Threat intelligence and threat detection indicators (IOC, IOA)☆52Updated 4 years ago
- PortPlow is a distributed port and system scanning & enumeration service. It enables the quick and automated enumeration of ports and ser…☆54Updated 7 months ago
- PSAttck is a light-weight framework for the MITRE ATT&CK Framework.☆38Updated 3 years ago
- Repository of resources for configuring a Red Team SIEM using Elastic☆101Updated 7 years ago
- ☆13Updated 5 years ago
- Simple SYSLOG client in Go☆22Updated last month
- SIEM Detection Use Case Library mapped to MITRE ATT&CK tactics and techniques☆12Updated 6 years ago
- An extensible honeypot framework☆93Updated 3 years ago
- This repo is dedicated to all my tricks, tweaks and modules for testing and hunting threats. This repo contains multiple directories whic…☆56Updated 7 years ago
- ☆53Updated 7 years ago
- ☆20Updated 5 years ago
- Old home of LimaCharlie, open source EDR☆31Updated last year
- YETI (Your Everyday Threat Intelligence) Integration to Elastic Stack☆16Updated 4 years ago
- Expert Investigation Guides☆52Updated 4 years ago