ine-labs / ThreatSeeker
ThreatSeeker: Threat Hunting via Windows Event Logs
☆115Updated last year
Related projects ⓘ
Alternatives and complementary repositories for ThreatSeeker
- Completely Risky Active-Directory Simulation Hub☆99Updated last year
- A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.☆148Updated 6 months ago
- Identify the accounts most vulnerable to dictionary attacks☆94Updated 3 months ago
- The LOLBins CTI-Driven (Living-Off-the-Land Binaries Cyber Threat Intelligence Driven) is a project that aims to help cyber defenders und…☆110Updated 7 months ago
- A collection of CVEs weaponized by ransomware operators☆78Updated this week
- PurpleLab is an efficient and readily deployable lab solution, providing a swift setup for cybersecurity professionals to test detection…☆246Updated last month
- Purpleteam scripts simulation & Detection - trigger events for SOC detections☆158Updated 2 weeks ago
- Repository where I hold random detection and threat hunting queries that I come up with based on different sources of information (or eve…☆39Updated 2 weeks ago
- Powershell tools used for Red Team / Pentesting.☆74Updated 10 months ago
- Advanced Bash script designed for conducting digital forensics on Linux systems☆130Updated 7 months ago
- PowerShell script designed to help Incident Responders collect forensic evidence from local and remote Windows devices.☆91Updated 2 months ago
- The purpose of this project is to publish and maintain the deployment PowerShell script that automates deployments for Active Directory C…☆232Updated 11 months ago
- Respotter is a Responder honeypot. Detect Responder in your environment as soon as it's spun up.☆180Updated 2 months ago
- ☆55Updated 6 months ago
- ☆72Updated this week
- God Mode Detection Rules☆131Updated 3 months ago
- Windows Malware Investigation Scripts & Docs☆75Updated 2 weeks ago
- An automated Breach and Attack Simulation lab with terraform. Built for IaC stability, consistency, and speed.☆169Updated 4 months ago
- Track C2 servers, tools, and botnets over time by framework and location☆36Updated last year
- ☆148Updated last year
- AHHHZURE is an automated deployment script that creates a vulnerable Azure cloud lab for offensive security practitioners and enthusiasts…☆101Updated 7 months ago
- Scripts and piece of codes used for Active Directory configuration☆81Updated last year
- ☆169Updated last month
- ☆158Updated 8 months ago
- ☆155Updated 11 months ago
- An open-source self-hosted purple team management web application.☆241Updated 3 months ago
- Hands-on cybersecurity projects to enhance skills in phishing investigation, malware analysis, network intrusion detection, and DDoS atta…☆88Updated 5 months ago
- A collection of various SIEM rules relating to malware family groups.☆62Updated 5 months ago
- Audit tool for Active Directory. Automates a lot of checks from a pentester perspective.☆156Updated last month
- This tool can gather a lot of info without any defender alerts. It is useful for Penetration testers, SOC Analysts, System administrators…☆28Updated 3 months ago