jymcheong / AutoTTP
Automated Tactics Techniques & Procedures
☆250Updated last year
Related projects ⓘ
Alternatives and complementary repositories for AutoTTP
- Test Blue Team detections without running any attack.☆271Updated 6 months ago
- ☆347Updated 3 years ago
- Simulating Adversary Operations☆93Updated 6 years ago
- A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.☆168Updated last year
- ☆279Updated 6 years ago
- A PowerShell script to interact with the MITRE ATT&CK Framework via its own API☆367Updated 5 years ago
- Toolset for research malware and Cobalt Strike beacons☆206Updated last year
- Personal compilation of APT malware from whitepaper releases, documents and own research☆255Updated 5 years ago
- Query and report user logons relations from MS Windows Security Events☆240Updated 6 years ago
- IR-Tools - PowerShell tools for IR☆128Updated 7 years ago
- Collecting & Hunting for IOCs with gusto and style☆236Updated 3 years ago
- All materials from our Black Hat 2018 "Subverting Sysmon" talk☆136Updated 6 years ago
- Historical list of {Cobalt Strike,NanoHTTPD} servers☆122Updated 5 years ago
- PowerShell No Agent Hunting☆108Updated 6 years ago
- Searches For Threat Hunting and Security Analytics☆239Updated 3 years ago
- Threat Alert Logic Repository☆89Updated 5 years ago
- A MITRE Caldera plugin written in Python 3 used to convert Red Canary Atomic Red Team Tests to MITRE Caldera Stockpile YAML ability files…☆71Updated 3 years ago
- ☆108Updated 7 years ago
- Allows you to quickly query a Windows machine for RAM artifacts☆218Updated 4 years ago
- Tools for the Computer Incident Response Team☆142Updated 7 years ago
- Detecting Lateral Movement with Machine Learning☆137Updated 7 years ago
- This repository contains all public indicators identified by 401trg during the course of our investigations. It also includes relevant ya…☆120Updated 3 years ago
- ATT&CK Evaluations website (DEPRECATED)☆59Updated 3 years ago
- Python script to decode common encoded PowerShell scripts☆215Updated 6 years ago
- ☆166Updated 4 years ago
- Deception based detection techniques mapped to the MITRE’s ATT&CK framework☆285Updated 7 years ago
- Mitre Att&ck Technique Emulation☆82Updated 5 years ago