fkie-cad / amides
An Adaptive Misuse Detection System
☆33Updated 2 months ago
Alternatives and similar repositories for amides:
Users that are interested in amides are comparing it to the libraries listed below
- Placeholder for my detection repo and misc detection engineering content☆43Updated last year
- Living off the False Positive!☆31Updated 4 months ago
- Providing Azure pipelines to create an infrastructure and run Atomic tests.☆50Updated last year
- This repository contains OpenIOC rules to aid in hunting for indicators of compromise and TTPs focused on Advanced Persistent Threat grou…☆22Updated last year
- Automatically spider the result set of a Censys/Shodan search and download all files where the file name or folder path matches a regex.☆27Updated last year
- Modular malware analysis artifact collection and correlation framework☆53Updated 8 months ago
- CIS Benchmark testing of Windows SIEM configuration☆44Updated last year
- An extension of the sigma standard to include security metrics.☆15Updated last year
- Linux #rootkit and #malware revealer☆21Updated 5 months ago
- Hundred Days of Yara Challenge☆12Updated 2 years ago
- This is a repo for fetching Applocker event log by parsing the win-event log☆30Updated 2 years ago
- SkillAegis is a platform to design, run, and monitor exercise scenarios, enhancing skills in applications like MISP and training users in…☆22Updated last month
- A simple tool designed to create Atomic Red Team tests with ease.☆36Updated last month
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆30Updated last month
- ☆19Updated 8 months ago
- Create a cool process tree like https://twitter.com/ACEResponder.☆34Updated last year
- Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!☆82Updated last year
- Assist analyst and threat hunters to understand Windows authentication logs and to analyze brutforce scenarios.☆18Updated last year
- A home for detection content developed by the delivr.to team☆63Updated last month
- ☆14Updated 8 months ago
- Invoke-AtomicAssessment is a powerful tool designed to facilitate adversary emulation by leveraging Atomic Red Team.☆31Updated last week
- Splunk Technology-AddOn for Aurora Sigma-Based EDR Agent. It helps parse and configure the necessary inputs to neatly consume Aurora EDR …☆13Updated 2 years ago
- ☆26Updated 3 years ago
- This repository contains sample log data that were collected after running adversary simulations in Microsoft 365☆20Updated 3 months ago
- VTC - Velociraptor Timeline Creator☆15Updated 8 months ago
- Method of finding interesting domains using keywords + JARMs☆13Updated last year
- Yara Rules for Modern Malware☆73Updated 10 months ago
- Offensive Research Guide to Help Defense Improve Detection☆29Updated last year
- yara detection rules for hunting with the threathunting-keywords project☆92Updated this week