mark-ignacio / bedr
a BPF-based Linux syscall monitor
☆10Updated 5 years ago
Alternatives and similar repositories for bedr
Users that are interested in bedr are comparing it to the libraries listed below
Sorting:
- IDS Utility Belt For Automating/Testing Various Things☆30Updated 4 years ago
- Duo MFA auditing tool to test users' likelihood of approving unexpected push notifications☆13Updated 7 years ago
- An active domain name query tool to help keep track of domain name movements...☆15Updated 4 years ago
- ☆30Updated 6 years ago
- Parsing MITRE EDR Evaluation results☆12Updated 6 years ago
- A Windows REG file to enable all default PowerShell logging on a system with PowerShell v5 installed☆16Updated 8 years ago
- Scripts to query local admins quickly☆9Updated 9 years ago
- Python parser for Red Canary's Atomic Red Team Yamls☆27Updated 6 years ago
- MalRecon - Basic Malware Reconnaissance and Analysis Tool☆26Updated 7 years ago
- Automatically attack all file shares within AD network environment. Exploiting weak permissions.☆17Updated 5 years ago
- SilkETW & SilkService☆40Updated 5 years ago
- My personal experience in Threat Hunting and knowledge gained so far.☆19Updated 7 years ago
- FastIR Agent is a Windows service to execute FastIR Collector on demand☆14Updated 8 years ago
- ☆12Updated 7 years ago
- Detect kerberos attacks in pcap files☆29Updated 9 years ago
- ☆14Updated 6 years ago
- List (or plunder) private repos/gists to which a token has access, including those of other users☆11Updated 3 years ago
- Slides from my AD Privesc talk at WAHCKon 2017☆16Updated 8 years ago
- Some rules, scripts of some use to us