lasq88 / socgholish_finderLinks
☆14Updated 2 years ago
Alternatives and similar repositories for socgholish_finder
Users that are interested in socgholish_finder are comparing it to the libraries listed below
Sorting:
- An experimental script to perform bulk parsing of arbitrary file features with YARA and console logging.☆21Updated 2 years ago
- Yara rules☆22Updated 2 years ago
- Scripts and tools accompanying HP Threat Research blog posts and reports.☆50Updated last year
- ☆34Updated 2 years ago
- Repo with supporting material for the talk titled "Cracking the Beacon: Automating the extraction of implant configurations"☆11Updated 5 months ago
- Accelerating the collection, processing, analysis and outputting of digital forensic artefacts.☆31Updated 5 months ago
- my MSTICpy practice and custom tools repository☆11Updated 2 months ago
- 100 Days of YARA to be updated with rules & ideas as the year progresses☆60Updated 2 years ago
- Threat Box Assessment Tool☆19Updated 3 years ago
- Jupyter Notebooks for Cyber Threat Intelligence☆35Updated last year
- ☆21Updated 4 months ago
- Scripts to for ready-to-use Velociraptor instance deployment in Azure☆14Updated 2 years ago
- Scripts and lists to help generate YARA friendly string mutations☆21Updated 2 years ago
- Offensive Research Guide to Help Defense Improve Detection☆31Updated 2 years ago
- Get-MiniTimeline - Triage Collection and Timeline Generation w/ KAPE☆31Updated last year
- A script to assist in processing forensic RAM captures for malware triage☆27Updated 4 years ago
- Domain Connectivity Analysis Tools to analyze aggregate connectivity patterns across a set of domains during security investigations☆43Updated 3 years ago
- ETW-Almulahaza is a consumer python-based tool that help you monitor ETW events of the operating system☆13Updated 3 years ago
- Quick ESXi Log Parser☆22Updated 6 months ago
- The core backend server handling API requests and task management☆43Updated 2 weeks ago
- A Modular MWDB Utility to Collect Fresh Malware Samples☆34Updated 4 years ago
- A home for detection content developed by the delivr.to team☆69Updated last month
- CryptnetURLCacheParser is a tool to parse CryptAPI cache files☆18Updated 11 months ago
- Public tools, scripts or code snippets that can help when working with our products☆46Updated 2 months ago
- THOR Thunderstorm Collectors☆24Updated 3 months ago
- ShellSweeping the evil.☆53Updated last year
- Powershell sandboxing utility☆18Updated this week
- Converts Sigma detection rules to a Splunk alert configuration.☆13Updated 4 years ago
- Scripts to integrate DFIR-IRIS, MISP and TimeSketch☆34Updated 3 years ago
- Tools and scripts to deploy and manage OpenRelik instances☆14Updated last month