AntiSyphon / BandBCampaigns
Backdoors & Breaches: Campaigns. These are short guides to help Incident Captains by giving them game ideas based on actual breaches.
☆34Updated last year
Alternatives and similar repositories for BandBCampaigns:
Users that are interested in BandBCampaigns are comparing it to the libraries listed below
- Conference presentations☆47Updated last year
- Tools for simulating threats☆181Updated last year
- Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.☆128Updated 2 years ago
- Collection of scripts/resources/ideas for attack surface reduction and additional logging to enable better threat hunting on Windows endp…☆38Updated 9 months ago
- A browser extension for threat hunting that provides one UI for different SIEMs/EDRs and simplifies investigation☆75Updated 8 months ago
- ☆55Updated 3 years ago
- Distribution of the SANS SEC504 Windows Cheat Sheet Lab☆67Updated 4 years ago
- Security Scripts and Sources for daily usage.☆51Updated last week
- This directory features proven systems that demonstrate value to your threat-informed efforts using metrics.☆108Updated 2 months ago
- ☆41Updated 8 months ago
- Identify Azure blobs using a wordlist of account name and container name strings☆32Updated 4 years ago
- Scripts for rapid Windows endpoint "tactical triage" and investigations with Velociraptor and KAPE☆109Updated 2 weeks ago
- ☆42Updated 2 years ago
- Threat Hunting Toolkit is a Swiss Army knife for threat hunting, log processing, and security-focused data science☆123Updated 3 weeks ago
- Repository of attack and defensive information for Business Email Compromise investigations☆241Updated last week
- Dashboard for conducting Backdoors and Breaches sessions over Zoom.☆113Updated 3 months ago
- InsightVM helpful SQL queries☆63Updated last month
- Audit Inspector is a tool for configuring and auditing Windows auditing.☆32Updated 4 months ago
- Windows Malware Investigation Scripts & Docs☆75Updated 2 months ago
- MISP to Sentinel integration☆62Updated 2 months ago
- RRR (Rapid Response Reporting) is a collection of Incident Response Report objects. They are designed to help incident responders provid…☆36Updated 2 years ago
- This guide describes a process for developing Cyber Threat Intelligence Priority Intelligence Requirements☆115Updated last year
- A tool that allows you to document and assess any security automation in your SOC☆45Updated 2 months ago
- Full of public notes and Utilities☆95Updated 2 months ago
- Notes on responding to security breaches relating to Azure AD☆97Updated 2 years ago
- ☆41Updated last year
- The PoLRBear Project☆35Updated 3 years ago
- ☆72Updated 3 months ago
- Dashboard for conducting Backdoors and Breaches sessions over Zoom.☆58Updated last week
- ☆54Updated last year