My external brain for cyber defense (WIP). A practical collection of field notes on hunting strategies and system principles. Documenting defensive mechanics and methods as I build this long-term library.
☆105Aug 27, 2026Updated last month
Alternatives and similar repositories for Blue_Team_Hunting_Field_Notes
Users that are interested in Blue_Team_Hunting_Field_Notes are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- PLAINBIT 세미나/컨퍼런스 발표자료 목록☆16Jul 30, 2026Updated 2 months ago
- An AWS CloudTrail exported logs analyzer tool☆21Jul 26, 2026Updated 2 months ago
- Deep Packet Inspection • Traffic Forensics • Network Threat Detection☆56Feb 20, 2026Updated 7 months ago
- This repository contains various threat hunting tools written in Python and is documented in the series Python Threat Hunting Tools which…☆22Nov 16, 2023Updated 2 years ago
- Free educational content on reverse engineering and malware analysis from the FLARE team☆1,490Mar 31, 2026Updated 6 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Cmdlets for capturing Windows Events☆14Mar 11, 2022Updated 4 years ago
- Spin up a fully configured, host‑only malware analysis lab with FlareVM, REMnux or CAPE Sandbox using a few repeatable commands.☆36Aug 15, 2026Updated last month
- Shattering the 1:10 barrier. A high-velocity alternative to Plaso for the modern IR landscape☆18Jul 6, 2026Updated 3 months ago
- A PowerShell-based script to analyze network logs from CSV files and detect potential beaconing behavior. Supports VirusTotal integration…☆17May 11, 2025Updated last year
- Incident Response documents and tooling☆132Jul 22, 2026Updated 2 months ago
- A curated collection of DFIR skills and workflows for InfoSec practitioners.☆323May 14, 2026Updated 4 months ago
- A CTI program management and production platform built around MISP☆43Updated this week
- ☆22Apr 1, 2026Updated 6 months ago
- This is a repository dedicated to the DFIR journey. Contains notes, reflections and links to tools.☆123May 8, 2026Updated 5 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret …☆374Sep 8, 2026Updated last month
- Advanced Threat Hunting: Ransomware Group☆29Jul 9, 2025Updated last year
- This repository contains detection and threat hunting queries created by NVISO’s CSIRT and SOC teams.☆20Jun 25, 2026Updated 3 months ago
- We took PersistenceSniper, merged it with Python, and misspelled it on purpose. Meet PyrsistenceSniper.☆273Sep 4, 2026Updated last month
- Triage automation tool☆23Sep 28, 2026Updated last week
- The most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl)…☆31Jul 28, 2026Updated 2 months ago
- A GUI tool used to parse Sysmon log and display as process tree☆18Mar 21, 2026Updated 6 months ago
- This repository dedicated to collect SIEM practice labs (Splunk and Elastic) from various cybersecurity training platforms☆68Oct 3, 2026Updated last week
- A repo to hold KQL queries as part of my 100 days of KQL effort.☆19Aug 5, 2026Updated 2 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- A starter pack of resources to help you get started in Detection Engineering.☆197Jun 4, 2026Updated 4 months ago
- Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MIT…☆180Updated this week
- Cyber Threat Intelligence☆83Dec 7, 2025Updated 10 months ago
- PowerShell-based Windows Server Security Audit Engine by Cyb3rint3l Labs. Measures alignment with the NIS2 directive and maps findings to…☆48Feb 1, 2026Updated 8 months ago
- Secret Key Scanner, Sensitive Directory Finder, Security Headers Analyzer, Risk Scoring, Exportable HTML Reports.☆20Nov 30, 2025Updated 10 months ago
- Process hunting Toolkit is toolkit capable of hunting down malicious processes on Windows☆14Jan 31, 2025Updated last year
- An exercise to practice deobfuscating PowerShell Scripts.☆26Feb 10, 2023Updated 3 years ago
- KQL Queries. Microsoft Defender, Microsoft Sentinel☆934Updated this week
- Triaging Windows event logs based on SANS Poster☆51Nov 22, 2025Updated 10 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- MISP to Microsoft Defender integration☆19Jul 9, 2026Updated 3 months ago
- bitCollector - DFIR (Digital Forensics and Incident Response) Triage Collector☆14Aug 18, 2025Updated last year
- Documentation and tools to curate Sigma rules for Windows event logs into easier to parse rules.☆16Oct 22, 2025Updated 11 months ago
- Automated n8n workflow for ransomware threat monitoring using ransomware.live API and Claude AI — companion to the SANS Ransomware Intell…☆22Apr 15, 2026Updated 5 months ago
- Track C2 servers, tools, and botnets over time by framework and location☆16Aug 17, 2025Updated last year
- DFIR LABS - A compilation of challenges that aims to provide practice in simple to advanced concepts in the following topics: Digital For…☆601Sep 20, 2026Updated 2 weeks ago
- Easily create index of your SANS books☆19Oct 28, 2022Updated 3 years ago