delivr-to / detectionsLinks
A home for detection content developed by the delivr.to team
☆69Updated 3 months ago
Alternatives and similar repositories for detections
Users that are interested in detections are comparing it to the libraries listed below
Sorting:
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆78Updated 2 weeks ago
- Small-scale threat emulation and detection range built on Elastic and Atomic Redteam.☆38Updated last year
- Baseline a Windows System against LOLBAS☆27Updated last year
- Placeholder for my detection repo and misc detection engineering content☆43Updated last year
- ShellSweeping the evil.☆52Updated 11 months ago
- Sigma detection rules for hunting with the threathunting-keywords project☆55Updated 2 months ago
- This repository aims to collect and document indicators from the different C2's listed in the C2-Matrix☆72Updated 3 years ago
- simple webapp for converting sigma rules into siem queries using the pySigma library☆48Updated last year
- Scripts and tools accompanying HP Threat Research blog posts and reports.☆50Updated last year
- Supporting materials for my "Intelligence-Led Adversarial Threat Modelling with VECTR" workshop☆68Updated 2 weeks ago
- Simple PowerShell script to enable process scanning with Yara.☆93Updated 2 years ago
- Library of threat hunts to get any user started!☆44Updated 4 years ago
- ☆87Updated last year
- Active C&C Detector☆154Updated last year
- The core backend server handling API requests and task management☆39Updated this week
- YARA rule analyzer to improve rule quality and performance☆101Updated last month
- Repo containing various intel-based resources such as threat research, adversary emulation/simulation plan and so on☆82Updated last year
- ☆42Updated last year
- CarbonBlack EDR detection rules and response actions☆71Updated 8 months ago
- VelociraptorMCP is a Model Context Protocol bridge for exposing LLMs to MCP clients.☆27Updated this week
- A simple tool designed to create Atomic Red Team tests with ease.☆43Updated 2 months ago
- The ultimate repository for remotely deploying Crowdstrike sensors quickly and discreetly on any other EDR platform.☆23Updated this week
- Cloud, CDN, and marketing services leveraged by cybercriminals and APT groups☆60Updated 2 years ago
- Create a cool process tree like https://twitter.com/ACEResponder.☆35Updated 2 years ago
- Yara Rules for Modern Malware☆77Updated last year
- This project is an Ansible Role to execute Atomic Red Team tests against multiple machines by wrapping Invoke-AtomicRedTeam☆27Updated 10 months ago
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆33Updated last month
- ☆27Updated 4 years ago
- The Eventlog Compendium is the go-to resource for understanding Windows Event Logs.☆43Updated last month
- 100 Days of YARA to be updated with rules & ideas as the year progresses☆60Updated 2 years ago