atc-project / atc-data
Actionable data for Security Operations
☆18Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for atc-data
- Hunting Queries for Microsoft Defender Security Center https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defe…☆36Updated 3 years ago
- Automatic detection engineering technical state compliance☆51Updated 4 months ago
- ☆41Updated 7 months ago
- OSSEM Data Dictionaries☆59Updated 3 months ago
- gundog - guided hunting in Microsoft Defender☆52Updated 3 years ago
- List of PowerShell commands and commandlets that should be in your Powershel watchlist☆38Updated 3 years ago
- Library of threat hunts to get any user started!☆40Updated 4 years ago
- Automated detection rule analysis utility☆29Updated 2 years ago
- Cyber Threats Detection Rules☆13Updated 2 months ago
- Supporting materials for my "Intelligence-Led Adversarial Threat Modelling with VECTR" workshop☆56Updated last week
- MITRE Shield website☆18Updated 3 years ago
- These are some of the commands which I use frequently during Malware Analysis and DFIR.☆25Updated 10 months ago
- ☆71Updated 5 months ago
- Small-scale threat emulation and detection range built on Elastic and Atomic Redteam.☆35Updated 11 months ago
- Useful access control entries (ACE) on system access control list (SACL) of securable objects to find potential adversarial activity☆88Updated 2 years ago
- A collection of useful PowerShell tools to collect, organize, and visualize Sysmon event data☆40Updated 4 years ago
- A collection of my presentations, blog posts, and other contributions to the information security community☆24Updated last month
- Repository for SPEED SIEM Use Case Framework☆52Updated 4 years ago
- Jupyter notebooks☆22Updated 4 years ago
- List of custom developed KQL queries to help proactive security teams hunt for opportunistic and sophisticated threat activity by develop…☆23Updated 3 years ago
- Attack Range to test detection against nativel serverless cloud services and environments☆35Updated 3 years ago
- MalwareAnalysis☆12Updated 3 years ago
- Provides detection capabilities and log conversion to evtx or syslog capabilities☆52Updated 2 years ago
- PowerHunt is a modular threat hunting framework written in PowerShell that leverages PowerShell Remoting for data collection on scale.☆60Updated 7 months ago
- PowerSponse is a PowerShell module focused on targeted containment and remediation during incident response.☆38Updated 2 years ago
- Collects a listing of MITRE ATT&CK Techniques, then discovers Splunk ESCU detections for each technique☆65Updated 8 months ago
- ☆43Updated last month
- Incident Response Report Using GitHub-Sphinx☆19Updated 5 years ago
- Azure function to insert MISP data in to Azure Sentinel☆30Updated 2 years ago