OTRF / SANS-BlueTeamSummit-2022Links
Repo to track SANS BlueTeam Summit Presentation
☆23Updated 2 years ago
Alternatives and similar repositories for SANS-BlueTeamSummit-2022
Users that are interested in SANS-BlueTeamSummit-2022 are comparing it to the libraries listed below
Sorting:
- ☆29Updated 4 years ago
- Small-scale threat emulation and detection range built on Elastic and Atomic Redteam.☆38Updated last year
- ☆47Updated last month
- Library of threat hunts to get any user started!☆44Updated 4 years ago
- ☆27Updated 4 years ago
- User Feedback Space of #MitreAssistant☆37Updated 2 years ago
- ☆16Updated 2 years ago
- Collects a listing of MITRE ATT&CK Techniques, then discovers Splunk ESCU detections for each technique☆67Updated last year
- Repo with supporting material for the talk titled "Cracking the Beacon: Automating the extraction of implant configurations"☆11Updated 4 months ago
- ☆21Updated 2 years ago
- An experimental script to perform bulk parsing of arbitrary file features with YARA and console logging.☆21Updated 2 years ago
- ☆21Updated 3 years ago
- My Jupyter Notebooks☆36Updated 2 months ago
- A completely unsupported set of scripts used in SANS FOR572, Advanced Network Forensics and Analysis☆27Updated last week
- Slides of my public talks☆55Updated last year
- A CALDERA plugin☆26Updated 10 months ago
- Helping Incident Responders hunt for potential persistence mechanisms on UNIX-based systems.☆15Updated last year
- Security Content for the PEAK Threat Hunting Framework☆29Updated last year
- Send High & New Incidents to The Hive incident management Platform☆18Updated 4 years ago
- Tool used to perform threat intelligence against packet data☆35Updated 4 months ago
- Defensive Origins Training Schedule☆38Updated last year
- ☆58Updated 3 years ago
- Powershell Scripts to work on Crowdstrike Falcon that pull back raw data relevant to forensic investigation☆22Updated 5 months ago
- A collection of Sigma rules organized by MITRE ATT&CK technique☆17Updated 3 years ago
- Winterfell hunt is a python script to perform auto threat hunting for malicious activities in windows OS based on collected data by winte…☆15Updated 4 years ago
- Repo of python/bash scripts for identifying IoC's in threat feed and other online tools☆27Updated 4 years ago
- A project that aims to automate Volatility3 at scale with the use of cloud strength and the power of KQL inside ADX.☆16Updated 5 months ago
- Intel Retrieval Augmented Generation (RAG) Utilities☆90Updated last year
- VelociraptorMCP is a Model Context Protocol bridge for exposing LLMs to MCP clients.☆28Updated last week
- Script to automate Linux live evidence collection☆27Updated 2 years ago