honeyswarm / honeyswarm
HoneyPot Orchestration
☆8Updated last year
Related projects: ⓘ
- Supporting material for my presentation "Adversarial Threat Modelling — A Practical Approach to Purple Teaming in the Enterprise"☆50Updated 2 years ago
- Compilation of resources to help with Adversary Simulation automation harness☆99Updated 4 years ago
- Hunt malware with Volatility☆46Updated 4 months ago
- ☆19Updated 3 years ago
- A happy place for detection engineers, purple teamers and threat hunters focusing on macOS.☆20Updated 2 years ago
- Automated detection rule analysis utility☆29Updated last year
- Automatic detection engineering technical state compliance☆49Updated 2 months ago
- ☆76Updated 6 years ago
- This repository aims to collect and document indicators from the different C2's listed in the C2-Matrix☆72Updated 2 years ago
- See adversary, do adversary: Simple execution of commands for defensive tuning/research (now with more ELF on the shelf)☆102Updated last year
- TA505+ Adversary Simulation☆64Updated 3 years ago
- A list of Mitre Caldera compatible emulation-plans☆14Updated 3 years ago
- Threat Box Assessment Tool☆19Updated 3 years ago
- ☆40Updated 5 months ago
- Machine Interrogation To Identify Gaps & Techniques for Execution☆32Updated 2 years ago
- labs_modern_malware_c2 Originally supporting Defcon workshop, will morph into Attack Defend for C2.☆18Updated 2 years ago
- Repository for SPEED SIEM Use Case Framework☆52Updated 4 years ago
- BlueSploit is a DFIR framework with the main purpose being to quickly capture artifacts for later review.☆32Updated 4 years ago
- The project was moved here https://github.com/atomic-threat-coverage/atomic-threat-coverage☆23Updated 5 years ago
- Library of threat hunts to get any user started!☆40Updated 4 years ago
- Recon Hunt Queries☆76Updated 3 years ago
- Carbon Black Response IR tool☆53Updated 3 years ago
- pocket guide for core threat hunting concepts☆23Updated 4 years ago
- Detect possible sysmon logging bypasses given a specific configuration☆107Updated 5 years ago
- Random notes collected on the intertubes relating to DFIR☆32Updated last year
- A repo to document API functions mapped to security events across diverse platforms☆74Updated 4 years ago
- Incident response teams usually working on the offline data, collecting the evidence, then analyze the data☆44Updated 2 years ago
- Threat Hunter's Knowledge Base☆21Updated 2 years ago
- Attack Tool Timing and Reporting - Structured Attack Logging Format☆21Updated last year
- PSAttck is a light-weight framework for the MITRE ATT&CK Framework.☆38Updated 2 years ago