blwhit / Document-SOC-SIEM-HomelabView external linksLinks
Cyber Attack/Defense home lab using Sliver, LimaCharlie [SIEM], & VM's to simulate C&C, Threat Detection, etc.
☆12Aug 31, 2023Updated 2 years ago
Alternatives and similar repositories for Document-SOC-SIEM-Homelab
Users that are interested in Document-SOC-SIEM-Homelab are comparing it to the libraries listed below
Sorting:
- Creating a remote keylogger in Python and disguising the executable as a JPEG.☆12Aug 30, 2023Updated 2 years ago
- ☆11Feb 9, 2023Updated 3 years ago
- 🌌 Real-time threat detection for smart contracts☆10May 16, 2023Updated 2 years ago
- ETHICAL-HACKING☆12Dec 20, 2023Updated 2 years ago
- NTAPI hook bypass with (semi) legit stack trace☆18May 9, 2023Updated 2 years ago
- Event Query Router☆12Aug 9, 2019Updated 6 years ago
- Alternative password shadowing scheme☆10Dec 1, 2025Updated 2 months ago
- Queries for Carbon Black Response☆11Feb 11, 2020Updated 6 years ago
- Bypassing AV, EDR, Application Whitelisting and ASR Rules☆13Apr 18, 2023Updated 2 years ago
- code for Graph Intelligence Enhanced Bi-Channel Insider Threat Detection paper☆13Aug 30, 2022Updated 3 years ago
- Legacy password hashing framework for PHP applications needing to support or having previously supported PHP below 5.5☆16Nov 22, 2024Updated last year
- This directory contains random scripts from threat hunting or malware research☆11Feb 15, 2018Updated 8 years ago
- Detection rules and threat hunting queries in Defender XDR and Azure Sentinel☆16Updated this week
- Small and highly portable detection tests based on MITRE's ATT&CK.☆12Jun 24, 2021Updated 4 years ago
- Implementation of bcrypt password hashing scheme☆12Jan 11, 2021Updated 5 years ago
- Graphical model of a TCP/IP stack which can be used as a cheatsheet when developing BPF filters.☆16Dec 10, 2019Updated 6 years ago
- Yet another fseventsd parser for macOS forensics☆11Jul 20, 2024Updated last year
- This project is an EDRSandblast fork, adding some features and custom pieces of code.☆14Jan 10, 2024Updated 2 years ago
- C2 Server for pentesting, exploitation, and payload creation☆12Jul 17, 2024Updated last year
- Threat Detection Rules (Snort/Sigma/Yara)☆14Jan 23, 2024Updated 2 years ago
- CLI Search for Security Operators of MITRE ATT&CK URLs☆17Jan 5, 2023Updated 3 years ago
- CSV Manager for AWS Security Hub exports SecurityHub findings to a CSV file and allows you to mass-update SecurityHub findings by modifyi…☆17Jul 23, 2025Updated 6 months ago
- Quick script to build host or investigation timelines using Carbon Black Response☆12Sep 25, 2018Updated 7 years ago
- Small container runtime for threat detection☆14Apr 13, 2025Updated 10 months ago
- EDR/AV Simulation for Malware Development☆13Oct 21, 2023Updated 2 years ago
- Cloud threat detection visualization from excalidraw☆12Apr 25, 2022Updated 3 years ago
- A hands-on workshop to learn how to do threat detection and response in AWS.☆11Sep 13, 2021Updated 4 years ago
- This batch script file wants to check your EDR systems detection and response capabilities in a more noisy way!☆11Jul 3, 2020Updated 5 years ago
- Generate representative samples from Pwned Passwords (HIBP)☆12Jan 6, 2022Updated 4 years ago
- BloodyAv is Custom Shell Code loader to Bypass Av and Edr.☆14Mar 21, 2022Updated 3 years ago
- Threat Detection System using Hybrid (Machine Learning + Lexical Analysis) learning Approach.☆11May 30, 2017Updated 8 years ago
- Test Suite for John the Ripper☆25Dec 28, 2025Updated last month
- Aggregated ATT&CK technique reporting data. Presented at Splunk GovSummit December 2022☆17Jul 18, 2025Updated 6 months ago
- The project “Behavioral Based Insider Threat Detection” leverages Deep learning to identify insider threats through user behavior and acc…☆11Sep 12, 2023Updated 2 years ago
- Short deep dive into Threat Hunting on AWS☆17Oct 15, 2023Updated 2 years ago
- Transparently call NTAPI via Halo's Gate with indirect syscalls.☆15Apr 26, 2024Updated last year
- A Multilayered AV/EDR Evasion Framework and AV Testing Tool.☆18Jun 28, 2025Updated 7 months ago
- 威胁检测规则集☆15Jul 5, 2019Updated 6 years ago
- Indirect Syscall invocation via thread hijacking☆26May 5, 2023Updated 2 years ago