A collection of threat hunting and detection engineering Jupyter notebooks accompanying the Weekly Purple Team YouTube channel. Each notebook provides detection logic to help security professionals understand both offensive techniques and defensive strategies.
☆17Feb 27, 2026Updated 5 months ago
Alternatives and similar repositories for ThreatHunting-JupyterNotebooks
Users that are interested in ThreatHunting-JupyterNotebooks are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A Python based tool to convert custom queries from Legacy BloodHound to BloodHound CE format, with the option to directly upload them to …☆38Oct 1, 2025Updated 10 months ago
- ☆15Jun 24, 2025Updated last year
- A stealthier approach to WMI-based command execution using Impacket without touching the disk.☆86Mar 15, 2026Updated 4 months ago
- Run CobaltStrike aggressorscript over TCP☆16Feb 9, 2026Updated 6 months ago
- Modular User-Defined Reflective Loader (UDRL) built on Crystal Palace for controlled DLL execution and evasion research.☆33Apr 14, 2026Updated 3 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- inspired by mr d0x filefix☆16Feb 4, 2026Updated 6 months ago
- One PsExec client to rule them all☆15Mar 25, 2026Updated 4 months ago
- Impersonate Windows tokens in Nim☆24Aug 4, 2025Updated last year
- rust port of pspy with support for process monitoring over dbus☆38Jan 4, 2026Updated 7 months ago
- Comprehensive Active Directory Enumeration tool using Netexec☆19Updated this week
- Cobalt Strike BOF to obtain location data☆30Jul 4, 2026Updated last month
- ☆20Mar 3, 2026Updated 5 months ago
- Combining KslDump and GhostKatz to dump LSASS using no-fix KslD.sys memory read to bypass PPL. Extracts MSV1_0 NT hashes and WDigest clea…☆45Mar 27, 2026Updated 4 months ago
- Extracting AsyncRAT configuration using CyberChef☆14May 4, 2022Updated 4 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A vibe-coded port of wiretap☆36Apr 25, 2026Updated 3 months ago
- ☆14Mar 9, 2023Updated 3 years ago
- Async PICO Hub is a work-in-progress framework to extend Cobalt Strike with custom event monitoring and in-process Asynchronous BOFs☆26Jun 4, 2026Updated 2 months ago
- mod to myaut2exe decompiler☆20Jul 28, 2017Updated 9 years ago
- Kerberos CNAME abuse PoC☆108Jan 27, 2026Updated 6 months ago
- Object file loader implemented as a post-ex DLL for asynchronous BOF execution.☆29Jul 23, 2026Updated 2 weeks ago
- Python script to leverage MSFT_MTProcess WMI class☆40Sep 17, 2025Updated 10 months ago
- Determine if the WebClient Service (WebDAV) is running on a remote system☆22Nov 28, 2025Updated 8 months ago
- Print the stack trace☆51Mar 8, 2026Updated 5 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Code and data for our paper "Onelogon: Taking over Active Directory Accounts via Netlogon" (WOOT’26).☆118Jun 22, 2026Updated last month
- bring your own clean ntdll (or other MS dlls)☆29Jul 14, 2025Updated last year
- A list of Cheatsheet compiled by CloudBreach Team☆50Jun 18, 2026Updated last month
- Used to get NTLMv2 Hashes from SMB☆28Oct 24, 2024Updated last year
- A Kubernetes Forensic Collection Framework for Azure Kubernetes Service☆44Feb 9, 2026Updated 6 months ago
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 3 months ago
- AdaptixC2 Templates☆34Apr 10, 2026Updated 4 months ago
- Mythic C2 CheatSheet for OSEP☆74Jun 17, 2026Updated last month
- Generate an Alphabetical Polymorphic Shellcode☆145Aug 19, 2025Updated 11 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Token impersonation in PowerShell to execute under the context of another user.☆25Oct 14, 2025Updated 9 months ago
- Utility tool to ingest CSV files into Kusto☆21Dec 17, 2025Updated 7 months ago
- Dump LSASS via physical memory read primitives in vulnerable kernel drivers☆35Jul 23, 2026Updated 2 weeks ago
- A sysmon configuration designed for monitoring RMM solutions from the LOLRMM framework on the OS Microsoft Windows. 10/11☆33Feb 17, 2026Updated 5 months ago
- ☆36Jul 1, 2025Updated last year
- Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but fo…☆175Jun 19, 2026Updated last month
- PowerShell script to generate ShellCode in various formats☆46Sep 25, 2024Updated last year