BinaryDefense / IcedDecrypt
IcedID Decryption Tool
☆27Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for IcedDecrypt
- A list of IOCs applicable to PoshC2☆24Updated 4 years ago
- ☆34Updated last year
- Generate YARA rules for OOXML documents.☆37Updated last year
- C# User Simulation☆33Updated 2 years ago
- Carbon Black Response IR tool☆53Updated 3 years ago
- ☆43Updated last year
- Get intelligence info (tags, mitre techniques, yara and more) and find similar malware in a fast and easy way☆18Updated 2 years ago
- Links to malware-related YARA rules☆14Updated 2 years ago
- Presentation materials for talks I've given.☆20Updated 5 years ago
- Rhaegal is a tool written in Python 3 used to scan Windows Event Logs for suspicious logs. Rhaegal uses custom rule format to detect sus…☆39Updated last year
- Yara rules☆20Updated last year
- Threat Box Assessment Tool☆19Updated 3 years ago
- ☆15Updated 2 years ago
- A list of Mitre Caldera compatible emulation-plans☆14Updated 3 years ago
- Slack C2bot that executes commands and returns the output.☆44Updated last year
- Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.☆76Updated 2 years ago
- ☆25Updated 3 years ago
- This repository aims to collect and document indicators from the different C2's listed in the C2-Matrix☆72Updated 2 years ago
- A simple command line program to help defender test their detections for network beacon patterns and domain fronting☆65Updated 2 years ago
- DFIR notes for Citrix ADC (NetScaler) appliances vulnerable to CVE-2019-19781☆45Updated 4 years ago
- Machine Interrogation To Identify Gaps & Techniques for Execution☆32Updated 2 years ago
- BlueSploit is a DFIR framework with the main purpose being to quickly capture artifacts for later review.☆32Updated 4 years ago
- ☆55Updated 4 years ago
- TA505+ Adversary Simulation☆65Updated 3 years ago
- Collection of YARA signatures from individual research☆42Updated last year
- Code and Slides of my BSides London 2019 presentation about Attacker Emulation using CALDERA☆22Updated 5 years ago
- ☆41Updated 7 months ago
- OSSEM Modular☆27Updated 4 years ago
- An Ansible role for installing Cobalt Strike.☆74Updated 3 months ago