elastic / endpoint-packageLinks
Repo for developing the endpoint package
☆27Updated last week
Alternatives and similar repositories for endpoint-package
Users that are interested in endpoint-package are comparing it to the libraries listed below
Sorting:
- Elastic Security Documentation☆86Updated last week
- ☆38Updated 3 months ago
- Combining Sealighter with unpatched exploits to run the Threat-Intelligence ETW Provider☆176Updated 2 years ago
- ETW based POC to identify direct and indirect syscalls☆187Updated 2 years ago
- A Golang CLI for the MITRE ATT&CK Framework☆13Updated 2 months ago
- Elastic Agent - single, unified way to add monitoring for logs, metrics, and other types of data to a host.☆186Updated this week
- Client/server code that impersonates TLS 1.3 to disguise C2 activity.☆70Updated 2 years ago
- elastic-package - Command line tool for developing Elastic Integrations☆62Updated this week
- A collection of projects demonstrating various commandline cloaking techniques on Linux☆58Updated 2 years ago
- Yapscan is a YAra based Process SCANner, aimed at giving more control about what to scan and giving detailed reports on matches.☆61Updated last year
- ☆74Updated 2 years ago
- Quickly search for references to a GUID in DLLs, EXEs, and drivers☆74Updated 3 years ago
- 🚧 Currently transfering TLP:CLEAR rules from TLP:AMBER repository...☆21Updated last year
- Protect your Domain Controllers by auditing and restricting LDAP requests☆172Updated last month
- PoC memory injection detection agent based on ETW, for offensive and defensive research purposes☆280Updated 4 years ago
- ☆114Updated 2 years ago
- A simple program to hook the current process to identify the manual syscall executions on windows☆259Updated 2 years ago
- A Python gRPC Client Library for Sliver☆70Updated 3 months ago
- Command line tool used for generating events corpus dynamically given a specific integration☆23Updated 5 months ago
- ☆28Updated 3 years ago
- This repository contains generated contextual data utilized by pyattck.☆19Updated 4 months ago
- Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles☆171Updated 3 weeks ago
- RDLL for Cobalt Strike beacon to silence sysmon process☆89Updated 2 years ago
- Implementation of Indirect Syscall technique to pop a calc.exe☆102Updated last year
- ☆16Updated last year
- OSSEM Data Dictionaries☆61Updated 5 months ago
- An implementation and proof-of-concept of Process Forking.☆226Updated 3 years ago
- ☆45Updated last year
- C++ WinRM API via Reflective DLL☆145Updated 3 years ago
- C# Utilities for Windows Notification Facility☆152Updated 3 months ago