NikolasBielski / Adversarial-Detection-Engineering-FrameworkLinks
A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples and real-world bypasses.
☆23Updated this week
Alternatives and similar repositories for Adversarial-Detection-Engineering-Framework
Users that are interested in Adversarial-Detection-Engineering-Framework are comparing it to the libraries listed below
Sorting:
- HoneyZure is a honeypot tool specifically designed for Azure environments, fully provisioned through Terraform. It leverages a Log Analyt…☆17Updated last year
- ☆14Updated 3 weeks ago
- Tool created for Red Team to test default credentials on SSH and WinRM and then execute scripts with those credentials before the passwor…☆40Updated 2 years ago
- A PoC to Simulate Ransomware Attack on AWS Environment☆32Updated last year
- python3 scripts to help with aws triage needs☆15Updated 3 years ago
- Find what egress ports are allowed☆46Updated 2 months ago
- Qemuno Framework☆24Updated 3 years ago
- ☆15Updated 3 years ago
- urlyzer is a URL parsing analysis tool.☆24Updated last year
- HTTP Headers Hashing (HHHash) is a technique used to create a fingerprint of an HTTP server based on the headers it returns.☆79Updated 2 years ago
- Living off the False Positive!☆41Updated last year
- Stupid Simple Detection Testing☆13Updated last year
- A home for detection content developed by the delivr.to team☆73Updated 5 months ago
- ☆91Updated this week
- ☆37Updated 4 years ago
- JamfHound is a python3 project designed to collect and identify attack paths in Jamf Pro tenants based on existing object permissions by …☆113Updated 5 months ago
- ☆40Updated 2 months ago
- Tail Certificate Transparency logs and extract hostnames☆127Updated 7 months ago
- Detonate malware on VMs and get logs & detection status☆76Updated last week
- A Golang library for interacting with the EPSS (Exploit Prediction Scoring System).☆30Updated 11 months ago
- Determine privileges from cloud credentials via brute-force testing.☆67Updated last year
- ☆60Updated 2 years ago
- ☆20Updated last year
- Fun tools around the EBS Direct API☆19Updated 4 years ago
- Automatic detection engineering technical state compliance☆55Updated last year
- self-hosted Azure OSINT tool☆32Updated 7 months ago
- Freyja is a Golang, Purple Team agent that compiles into Windows, Linux and macOS x64 executables.☆44Updated last year
- Eve is a JAMF exploitation toolkit used to interact with locally hosted JAMF servers and those hosted on jamfcloud.com.☆40Updated 4 months ago
- Examine Chrome extensions for security issues☆93Updated 2 months ago
- An extension of the sigma standard to include security metrics.☆15Updated 2 years ago