blwhit / EDR-Attack-and-Defense
Cyber Attack/Defense home lab using Sliver, LimaCharlie [SIEM], & VM's to simulate C&C, Threat Detection, etc.
☆9Updated last year
Alternatives and similar repositories for EDR-Attack-and-Defense:
Users that are interested in EDR-Attack-and-Defense are comparing it to the libraries listed below
- Repository for sharing examples of our artifacts data and for use in new analyst recruitment.☆49Updated this week
- Windows Malware Investigation Scripts & Docs☆81Updated 4 months ago
- This tool parses Windows EVTX logs to extract login and logout sessions from a security.evtx file. It uses a Tkinter GUI to let you selec…☆31Updated last month
- R3D SSH Hunter: The Ultimate SSH Key and Bad Guy Tracker☆12Updated 4 months ago
- An analytical challenge created to test junior analysts looking to try performing proactive and reactive cyber threat intelligence.☆196Updated 9 months ago
- Purpleteam scripts simulation & Detection - trigger events for SOC detections☆183Updated 3 months ago
- The LOLBins CTI-Driven (Living-Off-the-Land Binaries Cyber Threat Intelligence Driven) is a project that aims to help cyber defenders und…☆119Updated 11 months ago
- The Threat Actor Profile Guide for CTI Analysts☆106Updated last year
- CarbonBlack EDR detection rules and response actions☆71Updated 6 months ago
- A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.☆153Updated 10 months ago
- Some important DFIR Resources☆83Updated 2 years ago
- A collection of CVEs weaponized by ransomware operators☆111Updated 2 weeks ago
- A repository to share publicly available Velociraptor detection content☆139Updated this week
- A repository of my own Sigma detection rules.☆157Updated 6 months ago
- Harness the power of Splunk for your investigations☆95Updated this week
- Active C&C Detector☆153Updated last year
- Incident Response documents and tooling☆69Updated last year
- A library of reference materials, tools, and other resources to aid threat profiling, threat quantification, and cyber adversary defense☆85Updated last year
- A Python script for analyzing email files to extract IP addresses, URLs, headers, and attachments, with functionalities for defanging IPs…☆20Updated 5 months ago
- ☆159Updated last year
- SIEM Cheat Sheet☆73Updated last year
- A specification and style guide for YARA rules☆47Updated last year
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆84Updated last month
- A powerful home-lab focused on setting up Splunk SIEM and real-world use cases. If you’re interested to become SOC Analyst(Tier 1/2) , th…☆50Updated last year
- A repository to help CTI teams tackle the challenges around collection and research by providing guidance from experienced practitioners☆85Updated 5 months ago
- Some Threat Hunting queries useful for blue teamers☆125Updated 2 years ago
- Sigma rules to share with the community☆119Updated 2 months ago
- A browser extension for threat hunting that provides one UI for different SIEMs/EDRs and simplifies investigation☆77Updated 10 months ago
- Full of public notes and Utilities☆98Updated last month
- A community-driven repository for threat hunting ideas, methodologies, and research that serves as a central gathering place for hunters …☆217Updated 2 weeks ago