0x4D31 / santamonLinks
Lightweight macOS detection agent built on Santa’s Endpoint Security telemetry.
☆101Updated last month
Alternatives and similar repositories for santamon
Users that are interested in santamon are comparing it to the libraries listed below
Sorting:
- ☆51Updated last month
- ☆14Updated 3 weeks ago
- ☆137Updated 5 months ago
- A Golang library for interacting with the EPSS (Exploit Prediction Scoring System).☆30Updated 11 months ago
- ☆23Updated last year
- ForgeArmory provides TTPs that can be used with the TTPForge (https://github.com/facebookincubator/ttpforge).☆119Updated last month
- A PoC to Simulate Ransomware Attack on AWS Environment☆32Updated last year
- ☆41Updated last year
- The Event Maturity Matrix (EMM) is a comprehensive framework that provides clarity regarding the capabilities and nuances of SaaS audit l…☆30Updated 7 months ago
- This repository contains the research and components of our research into using Sigma for AWS Incident Response.☆31Updated 2 years ago
- ☆30Updated 2 weeks ago
- ☆40Updated 2 months ago
- AWS EKS Cluster Forensics☆23Updated 4 years ago
- ☆46Updated last year
- When good OAuth apps go rogue. Documents observed OAuth application tradecraft☆83Updated last month
- ☆36Updated 9 months ago
- ☆65Updated last year
- PoC shadow SaaS and insecure credential detection system using a browser extension.☆41Updated 2 months ago
- A ruleset to find potentially malicious code in macOS malware samples☆41Updated 2 years ago
- Repository that contains a set of purposefully erroneous Yara rules.☆61Updated 6 months ago
- HoneyZure is a honeypot tool specifically designed for Azure environments, fully provisioned through Terraform. It leverages a Log Analyt…☆17Updated last year
- ☆18Updated 3 weeks ago
- A POC to implement Detection-as-Code with Terraform and Sumo Logic.☆30Updated 2 years ago
- Spotter is a comprehensive Kubernetes security scanner that uses CEL-based rules to identify security vulnerabilities, misconfigurations,…☆69Updated 4 months ago
- Proof of Concepts for malicious maintainers: How to Tamper with Releases built with GitHub Actions Worfklows, presented at fwd:cloudsec E…☆77Updated 4 months ago
- pocket guide for core detection engineering concepts☆31Updated 2 years ago
- A catalog of services that can be publicly exposed within different cloud providers.☆14Updated last year
- Examine Chrome extensions for security issues☆93Updated 2 months ago
- Modron - Cloud security compliance☆34Updated last year
- An LLM and OCR based Indicator of Compromise Extraction Tool☆38Updated last year