My external brain for cyber defense (WIP). A practical collection of field notes on hunting strategies and system principles. Documenting defensive mechanics and methods as I build this long-term library.
☆104Aug 27, 2026Updated 3 weeks ago
Alternatives and similar repositories for Blue_Team_Hunting_Field_Notes
Users that are interested in Blue_Team_Hunting_Field_Notes are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- PLAINBIT 세미나/컨퍼런스 발표자료 목록☆16Jul 30, 2026Updated last month
- An AWS CloudTrail exported logs analyzer tool☆21Jul 26, 2026Updated last month
- Deep Packet Inspection • Traffic Forensics • Network Threat Detection☆56Feb 20, 2026Updated 7 months ago
- This repository contains various threat hunting tools written in Python and is documented in the series Python Threat Hunting Tools which…☆22Nov 16, 2023Updated 2 years ago
- Free educational content on reverse engineering and malware analysis from the FLARE team☆1,469Mar 31, 2026Updated 5 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Cmdlets for capturing Windows Events☆14Mar 11, 2022Updated 4 years ago
- Spin up a fully configured, host‑only malware analysis lab with FlareVM, REMnux or CAPE Sandbox using a few repeatable commands.☆35Aug 15, 2026Updated last month
- Shattering the 1:10 barrier. A high-velocity alternative to Plaso for the modern IR landscape☆17Jul 6, 2026Updated 2 months ago
- A PowerShell-based script to analyze network logs from CSV files and detect potential beaconing behavior. Supports VirusTotal integration…☆17May 11, 2025Updated last year
- Incident Response documents and tooling☆133Jul 22, 2026Updated last month
- A curated collection of DFIR skills and workflows for InfoSec practitioners.☆323May 14, 2026Updated 4 months ago
- A CTI program management and production platform built around MISP☆38Updated this week
- This is a repository dedicated to the DFIR journey. Contains notes, reflections and links to tools.☆121May 8, 2026Updated 4 months ago
- ☆22Apr 1, 2026Updated 5 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret …☆369Sep 8, 2026Updated last week
- Advanced Threat Hunting: Ransomware Group☆29Jul 9, 2025Updated last year
- This repository contains detection and threat hunting queries created by NVISO’s CSIRT and SOC teams.☆19Jun 25, 2026Updated 2 months ago
- We took PersistenceSniper, merged it with Python, and misspelled it on purpose. Meet PyrsistenceSniper.☆264Sep 4, 2026Updated 2 weeks ago
- A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV outp…☆335Feb 26, 2026Updated 6 months ago
- Triage automation tool☆23Aug 19, 2026Updated last month
- The most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl)…☆31Jul 28, 2026Updated last month
- A GUI tool used to parse Sysmon log and display as process tree☆18Mar 21, 2026Updated 5 months ago
- This repository dedicated to collect SIEM practice labs (Splunk and Elastic) from various cybersecurity training platforms☆68May 11, 2026Updated 4 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A repo to hold KQL queries as part of my 100 days of KQL effort.☆19Aug 5, 2026Updated last month
- A starter pack of resources to help you get started in Detection Engineering.☆196Jun 4, 2026Updated 3 months ago
- Cyber Threat Intelligence☆83Dec 7, 2025Updated 9 months ago
- PowerShell-based Windows Server Security Audit Engine by Cyb3rint3l Labs. Measures alignment with the NIS2 directive and maps findings to…☆47Feb 1, 2026Updated 7 months ago
- Secret Key Scanner, Sensitive Directory Finder, Security Headers Analyzer, Risk Scoring, Exportable HTML Reports.☆20Nov 30, 2025Updated 9 months ago
- Process hunting Toolkit is toolkit capable of hunting down malicious processes on Windows☆14Jan 31, 2025Updated last year
- An exercise to practice deobfuscating PowerShell Scripts.☆26Feb 10, 2023Updated 3 years ago
- KQL Queries. Microsoft Defender, Microsoft Sentinel☆933Updated this week
- Triaging Windows event logs based on SANS Poster☆50Nov 22, 2025Updated 9 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- MISP to Microsoft Defender integration☆18Jul 9, 2026Updated 2 months ago
- bitCollector - DFIR (Digital Forensics and Incident Response) Triage Collector☆14Aug 18, 2025Updated last year
- Documentation and tools to curate Sigma rules for Windows event logs into easier to parse rules.☆16Oct 22, 2025Updated 10 months ago
- Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MIT…☆176Updated this week
- Track C2 servers, tools, and botnets over time by framework and location☆16Aug 17, 2025Updated last year
- Automated n8n workflow for ransomware threat monitoring using ransomware.live API and Claude AI — companion to the SANS Ransomware Intell…☆22Apr 15, 2026Updated 5 months ago
- DFIR LABS - A compilation of challenges that aims to provide practice in simple to advanced concepts in the following topics: Digital For…☆591Nov 28, 2025Updated 9 months ago