Neo23x0 / Raccine
A Simple Ransomware Vaccine
☆943Updated 10 months ago
Related projects: ⓘ
- TrustedSec Sysinternals Sysmon Community Guide☆1,123Updated 3 months ago
- Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysi…☆1,224Updated last year
- Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detection…☆830Updated 2 years ago
- Sophos-originated indicators-of-compromise from published reports☆534Updated last week
- All sysmon event types and their fields explained☆528Updated 2 years ago
- WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)☆751Updated last year
- A forensics tool to convert the data in the Windows srum (System Resource Usage Monitor) database to an xlsx spreadsheet.☆593Updated 9 months ago
- Bloodhound Reporting for Blue and Purple Teams☆1,103Updated 3 weeks ago
- Defences against Cobalt Strike☆1,270Updated 2 years ago
- Rapidly Search and Hunt through Windows Forensic Artefacts☆2,715Updated 3 weeks ago
- An Active Defense and EDR software to empower Blue Teams☆1,226Updated last year
- ☆560Updated last year
- Online hash checker for Virustotal and other services☆808Updated 4 months ago
- Tools for hunting for threats.☆564Updated last year
- Sysmon configuration file template with default high-quality event tracing☆448Updated 7 months ago
- A post exploitation framework designed to operate covertly on heavily monitored environments☆2,024Updated 2 years ago
- A repository of DFIR-related Mind Maps geared towards the visual learners!☆507Updated 2 years ago
- RegRipper3.0☆534Updated 3 weeks ago
- Digital Forensics Investigation Platform☆757Updated last month
- A collection of red team and adversary emulation resources developed and released by MITRE.☆490Updated 3 years ago
- A list of vulnerabilities or design flaws that Microsoft does not intend to fix. Since the number is growing, I decided to make a list. T…☆933Updated 3 years ago
- A PrintNightmare (CVE-2021-34527) Python Scanner. Scan entire subnets for hosts vulnerable to the PrintNightmare RCE☆777Updated 4 months ago
- Repository of YARA rules made by Trellix ATR Team☆560Updated 8 months ago
- ReversingLabs YARA Rules☆744Updated last week
- ScareCrow - Payload creation framework designed around EDR bypass.☆2,709Updated last year
- Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...☆997Updated 2 weeks ago
- CyLR - Live Response Collection Tool☆622Updated 2 years ago
- UAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of …☆741Updated 2 weeks ago
- Open EDR public repository☆2,224Updated 8 months ago
- Malwoverview is a first response tool used for threat hunting and offers intel information from Virus Total, Hybrid Analysis, URLHaus, Po…☆2,918Updated 2 months ago