martinkubecka / C2Detective
Application for detecting command and control (C2) communication through network traffic analysis.
☆14Updated last year
Alternatives and similar repositories for C2Detective:
Users that are interested in C2Detective are comparing it to the libraries listed below
- ☆22Updated last year
- My nim learning experiments☆11Updated 2 years ago
- Repository of Yara rules created by the Stratosphere team☆26Updated 3 years ago
- The repository accompanying the Buer Emulation workshop☆24Updated 3 years ago
- Code for profiling sandboxes - Initially an idea to profile sandboxes, the code is written to take enviromental variables and send them b…☆20Updated last year
- Malware campaigns and APTs research by BlackArrow☆18Updated 4 years ago
- Repository for LNK stuff☆30Updated 2 years ago
- ☆27Updated 5 months ago
- Triaging Windows event logs based on SANS Poster☆39Updated 2 years ago
- Malware and PCAP☆11Updated last year
- A repo to house files for our blogposts on blog.nviso.eu☆70Updated last month
- CyberWarFare Labs hands-on workshop on the topic "Detecting Adversarial Tradecrafts/Tools by leveraging ETW"☆49Updated 3 years ago
- ☆12Updated 2 years ago
- Adapt practically persistence steadiness strategies working at Windows 10 utilized by sponsored nation-state threat actors, as Turla, Pro…☆22Updated 4 years ago
- Symantec EDR Internals☆26Updated 3 years ago
- Sp00fer blog post -☆26Updated 2 years ago
- A collection of my presentation materials.☆17Updated 11 months ago
- This repository contains several AMSI bypasses. These bypasses are based on some very nice research that has been put out by some awesome…☆24Updated 2 years ago
- Writing Your Own Ticket to the Cloud Like APT: A Deep-dive to AD FS Attacks, Detections, and Mitigations☆12Updated 2 years ago
- Splunk Technology-AddOn for Aurora Sigma-Based EDR Agent. It helps parse and configure the necessary inputs to neatly consume Aurora EDR …☆13Updated 2 years ago
- ☆30Updated 5 months ago
- Just another useless C2 occupying space in some HDD somewhere.☆20Updated last year
- ☆15Updated last year
- ☆14Updated 3 years ago
- Scans a list of raccoon servers from Tria.ge and extracts the config☆15Updated last year
- NanoDumpInject from https://s3cur3th1ssh1t.github.io/Reflective-Dump-Tools/ , minor edits with a few syscalls☆11Updated 2 years ago
- Log4Shell IOCs from CERT Orange Cyberdefense Threat Intelligence Datalake☆18Updated 2 years ago
- Placeholder for my detection repo and misc detection engineering content☆43Updated last year
- A project created with an aim to emulate and test exfiltration of data over different network protocols.☆31Updated 2 years ago
- Work in Progress repo☆14Updated 6 years ago