JPCERTCC / LogonTracer
Investigate malicious Windows logon by visualizing and analyzing Windows event log
☆2,738Updated 5 months ago
Related projects ⓘ
Alternatives and complementary repositories for LogonTracer
- A toolset to make a system look as if it was the victim of an APT attack☆2,470Updated last year
- Windows Events Attack Samples☆2,248Updated last year
- ☆2,189Updated last year
- A repository of sysmon configuration modules☆2,664Updated 3 months ago
- YARA signature and IOC database for my scanners and tools☆2,486Updated this week
- Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis…☆2,508Updated 4 months ago
- A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more e…☆4,025Updated 9 months ago
- Wiki to collect Red Team infrastructure hardening resources☆4,152Updated 7 months ago
- Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term o…☆2,384Updated 2 months ago
- Interesting APT Report Collection And Some Special IOC☆2,439Updated this week
- Loki - Simple IOC and YARA Scanner☆3,402Updated 3 weeks ago
- Utilities for Sysmon☆1,489Updated 5 months ago
- Attack and defend active directory using modern post exploitation adversary tradecraft activity☆4,422Updated 2 weeks ago
- MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, i…☆2,934Updated 3 months ago
- A curated list of awesome YARA rules, tools, and people.☆3,565Updated this week
- Detect Tactics, Techniques & Combat Threats☆2,067Updated 2 weeks ago
- A Powershell incident response framework☆1,559Updated last year
- An Active Defense and EDR software to empower Blue Teams☆1,239Updated last year
- Virtual Machine for Adversary Emulation and Threat Hunting☆1,247Updated 4 years ago
- Automate the creation of a lab environment complete with security tooling and logging best practices☆4,648Updated 4 months ago
- An informational repo about hunting for adversaries in your IT environment.☆1,722Updated 3 years ago
- DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will auto…☆1,784Updated 4 months ago
- Digging Deeper....☆2,984Updated this week
- APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the …☆1,256Updated 2 weeks ago
- An asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR☆2,197Updated 11 months ago
- A tool to abuse Exchange services☆2,171Updated 5 months ago
- FakeNet-NG - Next Generation Dynamic Network Analysis Tool☆1,804Updated this week
- Automated Adversary Emulation Platform☆5,660Updated this week
- A collaborative, multi-platform, red teaming framework☆3,264Updated this week
- Mimikatz implementation in pure Python☆2,879Updated last month