My external brain for cyber defense (WIP). A practical collection of field notes on hunting strategies and system principles. Documenting defensive mechanics and methods as I build this long-term library.
☆102Aug 8, 2026Updated this week
Alternatives and similar repositories for Blue_Team_Hunting_Field_Notes
Users that are interested in Blue_Team_Hunting_Field_Notes are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- PLAINBIT 세미나/컨퍼런스 발표자료 목록☆16Jul 30, 2026Updated last week
- An AWS CloudTrail exported logs analyzer tool☆21Jul 26, 2026Updated 2 weeks ago
- Deep Packet Inspection • Traffic Forensics • Network Threat Detection☆55Feb 20, 2026Updated 5 months ago
- Spin up a fully configured, host‑only malware analysis lab with FlareVM, REMnux or CAPEv2 Sandbox using a few repeatable commands.☆24Updated this week
- This repository contains various threat hunting tools written in Python and is documented in the series Python Threat Hunting Tools which…☆19Nov 16, 2023Updated 2 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Free educational content on reverse engineering and malware analysis from the FLARE team☆1,411Mar 31, 2026Updated 4 months ago
- Cmdlets for capturing Windows Events☆14Mar 11, 2022Updated 4 years ago
- Shattering the 1:10 barrier. A high-velocity alternative to Plaso for the modern IR landscape☆16Jul 6, 2026Updated last month
- This repository contains detection and threat hunting queries created by NVISO’s CSIRT and SOC teams.☆18Jun 25, 2026Updated last month
- A curated collection of DFIR skills and workflows for InfoSec practitioners.☆321May 14, 2026Updated 2 months ago
- Incident Response documents and tooling☆128Jul 22, 2026Updated 2 weeks ago
- A PowerShell-based script to analyze network logs from CSV files and detect potential beaconing behavior. Supports VirusTotal integration…☆17May 11, 2025Updated last year
- This is a repository dedicated to the DFIR journey. Contains notes, reflections and links to tools.☆119May 8, 2026Updated 3 months ago
- A CTI program management and production platform built around MISP☆32Updated this week
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret …☆304Jul 27, 2026Updated 2 weeks ago
- ☆23Apr 1, 2026Updated 4 months ago
- Advanced Threat Hunting: Ransomware Group☆29Jul 9, 2025Updated last year
- A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV outp…☆333Feb 26, 2026Updated 5 months ago
- We took PersistenceSniper, merged it with Python, and misspelled it on purpose. Meet PyrsistenceSniper.☆243Mar 30, 2026Updated 4 months ago
- Triage automation tool☆22Jul 27, 2026Updated last week
- The most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl)…☆31Jul 28, 2026Updated last week
- A GUI tool used to parse Sysmon log and display as process tree☆18Mar 21, 2026Updated 4 months ago
- This repository dedicated to collect SIEM practice labs (Splunk and Elastic) from various cybersecurity training platforms☆66May 11, 2026Updated 2 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A repo to hold KQL queries as part of my 100 days of KQL effort.☆19Updated this week
- A starter pack of resources to help you get started in Detection Engineering.☆194Jun 4, 2026Updated 2 months ago
- Open-source desktop workbench for digital forensic analysis. Inspect ZIP/TAR/7z archives and iTunes/Android backups. Parse and view ABX, …☆41Updated this week
- Cyber Threat Intelligence☆83Dec 7, 2025Updated 8 months ago
- Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MIT…☆118Jul 15, 2026Updated 3 weeks ago
- KQL Queries. Microsoft Defender, Microsoft Sentinel☆923Updated this week
- PowerShell-based Windows Server Security Audit Engine by Cyb3rint3l Labs. Measures alignment with the NIS2 directive and maps findings to…☆47Feb 1, 2026Updated 6 months ago
- Secret Key Scanner, Sensitive Directory Finder, Security Headers Analyzer, Risk Scoring, Exportable HTML Reports.☆21Nov 30, 2025Updated 8 months ago
- Process hunting Toolkit is toolkit capable of hunting down malicious processes on Windows☆14Jan 31, 2025Updated last year
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- An exercise to practice deobfuscating PowerShell Scripts.☆26Feb 10, 2023Updated 3 years ago
- Triaging Windows event logs based on SANS Poster☆50Nov 22, 2025Updated 8 months ago
- bitCollector - DFIR (Digital Forensics and Incident Response) Triage Collector☆13Aug 18, 2025Updated 11 months ago
- MISP to Microsoft Defender integration☆18Jul 9, 2026Updated last month
- Documentation and tools to curate Sigma rules for Windows event logs into easier to parse rules.☆16Oct 22, 2025Updated 9 months ago
- A comprehensive Windows security auditing and threat detection toolkit. Features 58 production-ready PowerShell functions organized into …☆87Oct 20, 2025Updated 9 months ago
- Track C2 servers, tools, and botnets over time by framework and location☆16Aug 17, 2025Updated 11 months ago