NybbleHub / Bluekeep-Detection-RuleLinks
Bluekeep detection rule by using Apache Flink CEP (Complex Event Processing) Library and Markov Chain.
☆9Updated 5 years ago
Alternatives and similar repositories for Bluekeep-Detection-Rule
Users that are interested in Bluekeep-Detection-Rule are comparing it to the libraries listed below
Sorting:
- ☆41Updated 2 years ago
- Tool to manage user privileges☆29Updated 5 years ago
- ETWNetMonv3 is simple C# code for Monitoring TCP Network Connection via ETW & ETWProcessMon/2 is for Monitoring Process/Thread/Memory/Ima…☆40Updated 2 years ago
- Plaform independent reverse shell over https☆11Updated 5 years ago
- All necessary code in order to feed Sysmon data into Recurrent Neural Network☆17Updated 5 years ago
- ssdeep cluster analysis for malware files☆31Updated 5 years ago
- QuasarRAT analysis tools and research report☆27Updated last year
- A tool is used to infected a shellcode to PE file, the shellcode is packed at compile time and unpacked at runtime☆13Updated 5 years ago
- Links to malware-related YARA rules☆15Updated 2 years ago
- all published scripts devloped by ahmed khlief☆20Updated 5 years ago
- POC code to crash Windows Event Logger Service☆27Updated 4 years ago
- SqlServer Linked Password Dumper.☆16Updated 8 years ago
- Experiments on the Windows Internals☆30Updated 5 years ago
- Lightweight C# windows agent for Apfell☆17Updated 5 years ago
- Sources code extracted from malwares for analysis☆38Updated 2 years ago
- ☆21Updated 5 years ago
- Detecting PowerShell Empire, Metasploit Meterpreter and Cobalt Strike agents by payload size sequence analysis and host correlation☆16Updated 6 years ago
- I used this to see if an EDR is running in Safe Mode☆37Updated 4 years ago
- simple demo of using C# & System.Management.Automation.dll to run powershell code (b64 encoded) without powershell.exe☆14Updated 8 years ago
- Suricata rule and intel index☆31Updated last week
- Collection of malware ioc hashes from blog posts. A Python script is provided to search through it.☆17Updated 4 years ago
- Miscellaneous PowerShell scripts for red team activities☆16Updated 8 months ago
- Backdoor detection for VMware view☆13Updated 3 years ago
- C# Situational Awareness Script☆34Updated 6 years ago
- Create Cobalt Strike malleable C2 profiles with HTTPS configs☆18Updated 5 years ago
- Invoke-Decoder – A PowerShell script to decode/deobfuscate malware samples☆19Updated 4 years ago
- POC for utilizing wikipedia API for Command and Control☆29Updated 2 years ago
- HTTP Protocol Stack CVE-2021-31166☆13Updated 9 months ago
- automated sticky keys backdoor☆10Updated 9 years ago
- Example of async client/server sockets in .NET 5☆17Updated 4 years ago