mandiant / sunburst_countermeasures
☆561Updated last year
Alternatives and similar repositories for sunburst_countermeasures:
Users that are interested in sunburst_countermeasures are comparing it to the libraries listed below
- SunBurst DGA Decode Script☆208Updated 4 years ago
- A Splunk app mapped to MITRE ATT&CK to guide your threat hunts☆1,146Updated last year
- Re-play Security Events☆1,625Updated 11 months ago
- Sophos-originated indicators-of-compromise from published reports☆565Updated 3 weeks ago
- A collection of red team and adversary emulation resources developed and released by MITRE.☆498Updated 3 years ago
- Actionable analytics designed to combat threats☆981Updated 2 years ago
- Open Source Security Events Metadata (OSSEM)☆1,255Updated 2 years ago
- Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysi…☆1,252Updated last year
- Repository of YARA rules made by Trellix ATR Team☆576Updated last year
- An Active Defense and EDR software to empower Blue Teams☆1,262Updated last year
- Tools for hunting for threats.☆579Updated 4 months ago
- Scripts and a (future) library to improve users' interactions with the ATT&CK content☆585Updated last year
- Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups☆707Updated 2 years ago
- ☆1,064Updated 5 years ago
- Indicators from Unit 42 Public Reports☆706Updated last month
- A set of Zeek scripts to detect ATT&CK techniques.☆577Updated 8 months ago
- Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK☆1,065Updated 3 months ago
- ☆2,657Updated 11 months ago
- A collection of YARA rules we wish to share with the world, most probably referenced from http://blog.inquest.net.☆371Updated 2 years ago
- All sysmon event types and their fields explained☆543Updated 3 years ago
- ReversingLabs YARA Rules☆794Updated this week
- A curated list of awesome resources related to Mitre ATT&CK™ Framework☆593Updated 5 years ago
- Defences against Cobalt Strike☆1,283Updated 2 years ago
- Tool Analysis Result Sheet☆347Updated 7 years ago
- Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding. #nsac…☆860Updated 4 years ago
- Cyber Analytics Repository☆920Updated 11 months ago
- Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.☆912Updated last year
- The main project for the Unfetter-Discover application. This is the project that will hold the configuration files, the docker-compose f…☆411Updated 2 years ago
- DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.☆548Updated 3 years ago
- Online hash checker for Virustotal and other services☆822Updated 9 months ago