My external brain for cyber defense (WIP). A practical collection of field notes on hunting strategies and system principles. Documenting defensive mechanics and methods as I build this long-term library.
☆100Jul 10, 2026Updated last week
Alternatives and similar repositories for Blue_Team_Hunting_Field_Notes
Users that are interested in Blue_Team_Hunting_Field_Notes are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- PLAINBIT 세미나/컨퍼런스 발표자료 목록☆15Apr 24, 2026Updated 2 months ago
- An AWS CloudTrail exported logs analyzer tool☆20Jul 12, 2026Updated last week
- Deep Packet Inspection • Traffic Forensics • Network Threat Detection☆55Feb 20, 2026Updated 5 months ago
- Spin up a fully configured, host‑only malware analysis lab with FlareVM and REMnux using a few repeatable commands.☆22Mar 11, 2026Updated 4 months ago
- This repository contains various threat hunting tools written in Python and is documented in the series Python Threat Hunting Tools which…☆19Nov 16, 2023Updated 2 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Free educational content on reverse engineering and malware analysis from the FLARE team☆1,360Mar 31, 2026Updated 3 months ago
- Cmdlets for capturing Windows Events☆14Mar 11, 2022Updated 4 years ago
- Shattering the 1:10 barrier. A high-velocity alternative to Plaso for the modern IR landscape☆16Jul 6, 2026Updated 2 weeks ago
- This repository contains detection and threat hunting queries created by NVISO’s CSIRT and SOC teams.☆17Jun 25, 2026Updated 3 weeks ago
- A curated collection of DFIR skills and workflows for InfoSec practitioners.☆321May 14, 2026Updated 2 months ago
- A PowerShell-based script to analyze network logs from CSV files and detect potential beaconing behavior. Supports VirusTotal integration…☆17May 11, 2025Updated last year
- A CTI program management and production platform built around MISP☆32Jun 30, 2026Updated 2 weeks ago
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret …☆295Jun 6, 2026Updated last month
- ☆23Apr 1, 2026Updated 3 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Advanced Threat Hunting: Ransomware Group☆28Jul 9, 2025Updated last year
- We took PersistenceSniper, merged it with Python, and misspelled it on purpose. Meet PyrsistenceSniper.☆237Mar 30, 2026Updated 3 months ago
- Triage automation tool☆22Updated this week
- A GUI tool used to parse Sysmon log and display as process tree☆18Mar 21, 2026Updated 3 months ago
- The most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl)…☆31Updated this week
- A repo to hold KQL queries as part of my 100 days of KQL effort.☆19Apr 17, 2026Updated 3 months ago
- This repository dedicated to collect SIEM practice labs (Splunk and Elastic) from various cybersecurity training platforms☆66May 11, 2026Updated 2 months ago
- Open-source desktop workbench for digital forensic analysis. Inspect ZIP/TAR/7z archives and iTunes/Android backups. Parse and view ABX, …☆37Updated this week
- A starter pack of resources to help you get started in Detection Engineering.☆193Jun 4, 2026Updated last month
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Cyber Threat Intelligence☆82Dec 7, 2025Updated 7 months ago
- Secret Key Scanner, Sensitive Directory Finder, Security Headers Analyzer, Risk Scoring, Exportable HTML Reports.☆21Nov 30, 2025Updated 7 months ago
- MISP to Microsoft Defender integration☆18Jul 9, 2026Updated last week
- Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MIT…☆117Updated this week
- PowerShell-based Windows Server Security Audit Engine by Cyb3rint3l Labs. Measures alignment with the NIS2 directive and maps findings to…☆47Feb 1, 2026Updated 5 months ago
- Process hunting Toolkit is toolkit capable of hunting down malicious processes on Windows☆14Jan 31, 2025Updated last year
- An exercise to practice deobfuscating PowerShell Scripts.☆26Feb 10, 2023Updated 3 years ago
- bitCollector - DFIR (Digital Forensics and Incident Response) Triage Collector☆13Aug 18, 2025Updated 11 months ago
- A comprehensive Windows security auditing and threat detection toolkit. Features 58 production-ready PowerShell functions organized into …☆87Oct 20, 2025Updated 9 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Documentation and tools to curate Sigma rules for Windows event logs into easier to parse rules.☆16Oct 22, 2025Updated 8 months ago
- Automated n8n workflow for ransomware threat monitoring using ransomware.live API and Claude AI — companion to the SANS Ransomware Intell…☆22Apr 15, 2026Updated 3 months ago
- Track C2 servers, tools, and botnets over time by framework and location☆16Aug 17, 2025Updated 11 months ago
- DFIR LABS - A compilation of challenges that aims to provide practice in simple to advanced concepts in the following topics: Digital For…☆491Nov 28, 2025Updated 7 months ago
- ☆21Aug 14, 2025Updated 11 months ago
- Security automation with n8n ideas: 100+ Red/Blue/AppSec workflows, integrations, and ready-to-run playbooks.☆886Sep 20, 2025Updated 10 months ago
- MCP server for analyzing PE, ELF, and Mach-O binaries using LIEF☆24Mar 6, 2026Updated 4 months ago