SentineLabs / TrickBot-AnchorLinks
This is a repository for the public blog with Labs indicators of compromise.
☆10Updated 5 years ago
Alternatives and similar repositories for TrickBot-Anchor
Users that are interested in TrickBot-Anchor are comparing it to the libraries listed below
Sorting:
- Automated Payload Test Controller☆10Updated 8 years ago
- ☆22Updated 4 years ago
- This is a repository for the public blog with Labs indicators of compromise and code☆18Updated 5 years ago
- Repository of Information sharing on threats and indicators☆12Updated 5 years ago
- Indicators of compromise relating to our report on APT10's targeting of global MSPs☆10Updated 7 years ago
- ☆12Updated 4 years ago
- Notebooks created to attack and secure Active Directory environments☆27Updated 5 years ago
- Light System Examination Toolkit (LISET) - logs & activity & configuration gathering utility that comes handy in fast Windows incident re…☆31Updated 8 years ago
- Links to malware-related YARA rules☆15Updated 2 years ago
- Plugins for the Viper Framework☆14Updated 5 years ago
- Manticore's Public Threats Repository☆10Updated 4 years ago
- Do the unexpected with AD GPO processing☆9Updated 6 years ago
- A collection of threat intelligence data such as IOC, Yara and Snort/Suricata Rules etc.☆10Updated 5 years ago
- ☆20Updated 4 years ago
- Presentation materials for talks I've given.☆20Updated 5 years ago
- Toolkit to detected abnormal activities on a Windows machine.☆11Updated 9 years ago
- Speaking materials from conferences I've given☆9Updated 2 years ago
- A PowerShell script to prevent Sysmon from writing its events☆15Updated 5 years ago
- Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research☆53Updated 7 years ago
- Virustotal Data to Timesketch☆17Updated 6 years ago
- Docker projects to retain beacon source IPs using C2 relaying infra☆11Updated 6 years ago
- Script to pull newly-registered domains and check for similarity against a provided word list.☆13Updated 4 years ago
- The mission of Black Lotus Labs is to leverage our network visibility to both help protect customers and keep the internet clean.☆12Updated 4 years ago
- ☆14Updated 7 years ago
- C# User Simulation☆32Updated 2 years ago
- A set of YARA rules for the AIL framework to detect leak or information disclosure☆38Updated 5 months ago
- Microsoft Flow Attack Framework☆23Updated 5 years ago
- dankAlerts is powered by Sysmon and Memes. Would you notice if a suspicious process was recorded in the event log?☆18Updated 5 years ago
- Frontend to import Nmap Scan in ES, and frontend to make search☆10Updated 10 years ago
- Proof of concept communications from C# via a web browser process☆21Updated 6 years ago