op7ic / amphuntLinks
This repository contains advanced threat hunting scripts for Cisco Secure Endpoint API. The scripts leverage the AMP API to hunt for threats, analyze endpoint behavior, and detect potential compromises across the environment using API version 0 and 1.
☆14Updated 6 months ago
Alternatives and similar repositories for amphunt
Users that are interested in amphunt are comparing it to the libraries listed below
Sorting:
- Snapshot, patch, health-check, and potentially roll-back Windows VMs☆35Updated 7 years ago
- This repository contains all the config files and scripts used for our Open Source Endpoint monitoring project.☆35Updated 6 years ago
- Defence Against the Dark Arts☆34Updated 6 years ago
- THOR MITRE ATT&CK Framework Coverage☆25Updated 5 years ago
- PowerSponse is a PowerShell module focused on targeted containment and remediation during incident response.☆40Updated 3 years ago
- A few scripts I put together for testing purposes and to automate a few capabilities while doing IR. These scripts are also part of my bl…☆55Updated 7 years ago
- ☆13Updated 6 years ago
- Triage automation for suspect URLs☆13Updated 6 years ago
- PowerShell Memory Pulling script☆19Updated 10 years ago
- A few quick recipes for those that do not have much time during the day☆22Updated last year
- automate your MISP installs☆68Updated 5 years ago
- Information about most important hunts which can be performed by Threat hunters while searching for any adversary/threats inside the orga…☆15Updated 6 years ago
- Integrating Sysinternals Autoruns’ logs into Security Onion☆31Updated last year
- Threat intelligence and threat detection indicators (IOC, IOA)☆52Updated 5 years ago
- ☆39Updated 5 years ago
- A simple ReST server to lookup threat actors (by name, synonym or UUID) and returning the corresponding MISP galaxy information about the…☆50Updated 4 months ago
- Splunk App to assist Sysmon Threat Hunting☆38Updated 8 years ago
- ☆77Updated 6 years ago
- PSAttck is a light-weight framework for the MITRE ATT&CK Framework.☆38Updated 3 years ago
- Automatic Sender Policy Framework Reconnaissance☆19Updated 7 years ago
- Docker Container to deploy Mitre Caldera Automated Adversary Emulation System☆26Updated 5 years ago
- Incident Response Network Tools☆24Updated 4 years ago
- A utility to trawl phishing domains and attempt to identify phishing kits as well as other malicious activity☆36Updated 3 years ago
- Splunk Add-on for PowerShell provides field extraction for PowerShell event logs.☆17Updated 4 years ago
- Splunk app for Threat hunting☆15Updated 7 years ago
- incident response scripts☆18Updated 6 years ago
- OSSEC Decoder & Rulesets for Sysmon Events☆15Updated 10 years ago
- ☆33Updated last year
- Simple Powershell scripts to collect all Windows Event Logs from a host and parse them into one CSV timeline.☆32Updated 7 years ago
- ☆28Updated 6 months ago