My external brain for cyber defense (WIP). A practical collection of field notes on hunting strategies and system principles. Documenting defensive mechanics and methods as I build this long-term library.
☆104Aug 27, 2026Updated this week
Alternatives and similar repositories for Blue_Team_Hunting_Field_Notes
Users that are interested in Blue_Team_Hunting_Field_Notes are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- PLAINBIT 세미나/컨퍼런스 발표자료 목록☆16Jul 30, 2026Updated last month
- An AWS CloudTrail exported logs analyzer tool☆21Jul 26, 2026Updated last month
- Deep Packet Inspection • Traffic Forensics • Network Threat Detection☆56Feb 20, 2026Updated 6 months ago
- Spin up a fully configured, host‑only malware analysis lab with FlareVM, REMnux or CAPE Sandbox using a few repeatable commands.☆34Aug 15, 2026Updated 2 weeks ago
- This repository contains various threat hunting tools written in Python and is documented in the series Python Threat Hunting Tools which…☆19Nov 16, 2023Updated 2 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Free educational content on reverse engineering and malware analysis from the FLARE team☆1,440Mar 31, 2026Updated 4 months ago
- Cmdlets for capturing Windows Events☆14Mar 11, 2022Updated 4 years ago
- Shattering the 1:10 barrier. A high-velocity alternative to Plaso for the modern IR landscape☆16Jul 6, 2026Updated last month
- This repository contains detection and threat hunting queries created by NVISO’s CSIRT and SOC teams.☆19Jun 25, 2026Updated 2 months ago
- A curated collection of DFIR skills and workflows for InfoSec practitioners.☆321May 14, 2026Updated 3 months ago
- A PowerShell-based script to analyze network logs from CSV files and detect potential beaconing behavior. Supports VirusTotal integration…☆17May 11, 2025Updated last year
- Incident Response documents and tooling☆133Jul 22, 2026Updated last month
- This is a repository dedicated to the DFIR journey. Contains notes, reflections and links to tools.☆118May 8, 2026Updated 3 months ago
- A CTI program management and production platform built around MISP☆35Aug 14, 2026Updated 2 weeks ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret …☆345Updated this week
- ☆23Apr 1, 2026Updated 4 months ago
- Advanced Threat Hunting: Ransomware Group☆29Jul 9, 2025Updated last year
- A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV outp…☆334Feb 26, 2026Updated 6 months ago
- We took PersistenceSniper, merged it with Python, and misspelled it on purpose. Meet PyrsistenceSniper.☆248Mar 30, 2026Updated 5 months ago
- Triage automation tool☆22Aug 19, 2026Updated last week
- The most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl)…☆31Jul 28, 2026Updated last month
- A GUI tool used to parse Sysmon log and display as process tree☆18Mar 21, 2026Updated 5 months ago
- This repository dedicated to collect SIEM practice labs (Splunk and Elastic) from various cybersecurity training platforms☆66May 11, 2026Updated 3 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A repo to hold KQL queries as part of my 100 days of KQL effort.☆19Aug 5, 2026Updated 3 weeks ago
- A starter pack of resources to help you get started in Detection Engineering.☆195Jun 4, 2026Updated 2 months ago
- Open-source desktop workbench for digital forensic analysis. Inspect ZIP/TAR/7z archives and iTunes/Android backups. Parse and view ABX, …☆46Updated this week
- Cyber Threat Intelligence☆83Dec 7, 2025Updated 8 months ago
- KQL Queries. Microsoft Defender, Microsoft Sentinel☆927Aug 14, 2026Updated 2 weeks ago
- Secret Key Scanner, Sensitive Directory Finder, Security Headers Analyzer, Risk Scoring, Exportable HTML Reports.☆20Nov 30, 2025Updated 9 months ago
- PowerShell-based Windows Server Security Audit Engine by Cyb3rint3l Labs. Measures alignment with the NIS2 directive and maps findings to…☆47Feb 1, 2026Updated 6 months ago
- Process hunting Toolkit is toolkit capable of hunting down malicious processes on Windows☆14Jan 31, 2025Updated last year
- An exercise to practice deobfuscating PowerShell Scripts.☆26Feb 10, 2023Updated 3 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Triaging Windows event logs based on SANS Poster☆50Nov 22, 2025Updated 9 months ago
- MISP to Microsoft Defender integration☆18Jul 9, 2026Updated last month
- bitCollector - DFIR (Digital Forensics and Incident Response) Triage Collector☆14Aug 18, 2025Updated last year
- Documentation and tools to curate Sigma rules for Windows event logs into easier to parse rules.☆16Oct 22, 2025Updated 10 months ago
- A comprehensive Windows security auditing and threat detection toolkit. Features 58 production-ready PowerShell functions organized into …☆89Oct 20, 2025Updated 10 months ago
- Track C2 servers, tools, and botnets over time by framework and location☆16Aug 17, 2025Updated last year
- Automated n8n workflow for ransomware threat monitoring using ransomware.live API and Claude AI — companion to the SANS Ransomware Intell…☆22Apr 15, 2026Updated 4 months ago