nccgroup / KilledProcessCanary
A canary designed to minimize the impact from certain Ransomware actors
☆98Updated 4 years ago
Alternatives and similar repositories for KilledProcessCanary:
Users that are interested in KilledProcessCanary are comparing it to the libraries listed below
- This repository aims to collect and document indicators from the different C2's listed in the C2-Matrix☆72Updated 3 years ago
- My conference presentations☆66Updated last year
- ☆38Updated 3 years ago
- Using Microsoft 365 App Passwords for persistence☆23Updated 4 years ago
- This repository contains procedures found in the Feb 2022 conti leaks. They were taken from the "manual_teams_c" rocketchat channel in th…☆87Updated 3 years ago
- Useful access control entries (ACE) on system access control list (SACL) of securable objects to find potential adversarial activity☆90Updated 3 years ago
- Detect possible sysmon logging bypasses given a specific configuration☆108Updated 6 years ago
- Tool for assessing on-premises Microsoft servers authentication such as ADFS, Skype, Exchange, and RDWeb☆145Updated 4 years ago
- ☆108Updated 3 years ago
- Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.☆46Updated 5 years ago
- ☆41Updated last year
- PS-TrustedDocuments: PowerShell script to handle information on trusted documents for Microsoft Office☆35Updated 2 years ago
- Pushes Sysmon Configs☆88Updated 3 years ago
- A library for fast parse & import of Windows Eventlogs into Elasticsearch.☆85Updated 9 months ago
- A collection of tools to interact with Microsoft Security Response Center API☆97Updated last year
- A simple command line program to help defender test their detections for network beacon patterns and domain fronting☆69Updated 3 years ago
- PSAttck is a light-weight framework for the MITRE ATT&CK Framework.☆38Updated 3 years ago
- Machine Interrogation To Identify Gaps & Techniques for Execution☆32Updated 2 years ago
- Powershell Event Tracing Toolbox☆75Updated 3 years ago
- Blueteam operational triage registry hunting/forensic tool.☆145Updated last year
- YARI is an interactive debugger for YARA Language.☆88Updated 3 months ago
- Automated detection rule analysis utility☆29Updated 2 years ago
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆63Updated 2 years ago
- A tool to modify timestamps in a packet capture to a user selected date☆31Updated 3 years ago
- A list of IOCs applicable to PoshC2☆24Updated 4 years ago
- The tool creates a Microsoft Active Directory Domain with a structure and objects for learning.☆26Updated 3 years ago
- Indicator of Compromise Scanner for CVE-2019-19781☆94Updated 5 years ago
- Simple PowerShell script to enable process scanning with Yara.☆93Updated 2 years ago
- ☆98Updated 4 years ago
- Documentation and parsers for different anti-virus quarantine formats.☆42Updated 4 years ago