magoo / Vault-for-Incident-Responders
Things to know when DFIR occurs near a vault deployment.
☆43Updated 6 years ago
Related projects ⓘ
Alternatives and complementary repositories for Vault-for-Incident-Responders
- Python module for evaluation of AWS account best practices around incident handling readieness.☆55Updated 4 years ago
- Proof of Concept Zappa Based AWS Persistence and Attack Platform☆37Updated 4 years ago
- first commit☆20Updated last year
- Exfiltrate files via DNS☆96Updated 11 years ago
- Materials for the BSides NoVA/Charleston 2018 Bro Workshop☆14Updated last year
- Bro/Zeek integration with osquery☆95Updated 4 years ago
- threat-intelligence.eu website and repository of information about open standards, documents, methodologies and processes in threat intel…☆48Updated 2 years ago
- 🎯 Vulnerability Pryer - Prying context into your vulnerability data☆21Updated 2 years ago
- AWS Metadata Proxy for protection against SSRF☆68Updated 4 years ago
- Duo MFA auditing tool to test users' likelihood of approving unexpected push notifications☆13Updated 6 years ago
- Core incident handling plugins for aws_ir cli, incident pony, and more.☆21Updated 6 years ago
- Legal, procedural and policies document templates for operating MISP and information sharing communities☆37Updated last year
- A packer utility to create and capture DFIR Image for use AWS & Azure☆14Updated 5 years ago
- Looks for GitHub org users without 2FA turned on☆9Updated 8 years ago
- Salesforce Policy Deviation Checker☆30Updated 4 years ago
- defendA Data Lake. A firehose pipeline to athena providing enrichment and normalization for security events☆16Updated last year
- Osquery Mangement Server☆114Updated 4 years ago
- SightingDB is a database for Sightings☆21Updated last year
- [DEPRECATED] A quickstart demo for Kolide tools☆52Updated 6 years ago
- Web based analysis platform for use with the AWS_IR command line tool.☆17Updated 8 years ago
- A place for documenting threats and mitigations related to containers orchestrators (Kubernetes, Swarm etc)☆25Updated 6 years ago
- Repository for Endpoint Security Testing☆35Updated 6 years ago
- module for osquery to load Bro logs into tables☆28Updated 9 years ago
- Launchd daemon that reports major OSX modifications through growl☆16Updated 9 years ago
- ansible role to setup MISP, Malware Information Sharing Platform & Threat Sharing☆52Updated last week
- Honeypot log processor to create OTX Pulse entries☆29Updated 10 months ago