ahmedkhlief / APT-Hunter
APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity
☆1,333Updated 6 months ago
Alternatives and similar repositories for APT-Hunter:
Users that are interested in APT-Hunter are comparing it to the libraries listed below
- Invoke-AtomicRedTeam is a PowerShell module to execute tests as defined in the [atomics folder](https://github.com/redcanaryco/atomic-red…☆900Updated last week
- Open Source EDR for Windows☆1,213Updated 2 years ago
- Defences against Cobalt Strike☆1,283Updated 2 years ago
- An Active Defense and EDR software to empower Blue Teams☆1,274Updated last year
- Windows Events Attack Samples☆2,352Updated 2 years ago
- Automatically created C2 Feeds☆608Updated this week
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆710Updated last month
- VECTR is a tool that facilitates tracking of your red and blue team testing activities to measure detection and prevention capabilities a…☆1,464Updated last week
- ☆515Updated 7 months ago
- Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders☆902Updated last year
- Detect Tactics, Techniques & Combat Threats☆2,152Updated last week
- ☆543Updated last year
- Open Source Security Events Metadata (OSSEM)☆1,265Updated 2 years ago
- Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.☆566Updated 3 months ago
- A collection of red team and adversary emulation resources developed and released by MITRE.☆505Updated 4 years ago
- A Splunk app mapped to MITRE ATT&CK to guide your threat hunts☆1,156Updated last year
- Bloodhound Reporting for Blue and Purple Teams☆1,184Updated 2 months ago
- Elastic Security detection content for Endpoint☆1,183Updated this week
- A toolset to make a system look as if it was the victim of an APT attack☆2,584Updated last year
- TrustedSec Sysinternals Sysmon Community Guide☆1,212Updated 11 months ago
- Hunting queries and detections☆793Updated 3 months ago
- This project aims to compare and evaluate the telemetry of various EDR products.☆1,792Updated this week
- Ransomware simulator written in Golang☆436Updated 2 years ago
- Cyber Analytics Repository☆934Updated last year
- Sophos-originated indicators-of-compromise from published reports☆581Updated last month
- A set of Zeek scripts to detect ATT&CK techniques.☆587Updated 10 months ago
- A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the …☆1,651Updated 6 months ago
- An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.☆1,880Updated last year
- Investigate malicious Windows logon by visualizing and analyzing Windows event log☆2,884Updated 10 months ago
- Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detection…☆850Updated 3 years ago