optiv / Yara-Rules
☆9Updated 3 years ago
Alternatives and similar repositories for Yara-Rules:
Users that are interested in Yara-Rules are comparing it to the libraries listed below
- A list of IOCs applicable to PoshC2☆24Updated 4 years ago
- BloodHound Data Scanner☆44Updated 4 years ago
- Threat Mitigation Strategies☆25Updated last year
- Tool to perform lateral movement between AAD joined devices☆53Updated 2 years ago
- Extracts Azure authentication tokens from PowerShell process minidumps.☆23Updated last year
- Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable…☆17Updated 3 years ago
- A PowerShell script that checks for dangerous ACLs on system hives and shadows☆28Updated 3 years ago
- This is a repo for fetching Applocker event log by parsing the win-event log☆30Updated 2 years ago
- Creates an ATT&CK Navigator map of an Adversary Emulation Plan☆16Updated 3 years ago
- Scripts to automate standing up apache2 with mod_rewrite in front of C2 servers.☆46Updated 3 years ago
- A mini project to exfiltrate data via QR codes☆19Updated last month
- BloodCheck enables Red and Blue Teams to manage multiple Neo4j databases and run Cypher queries against a BloodHound dataset.☆17Updated 3 years ago
- Python Script for SAML2 Authentication Passwordspray☆38Updated last year
- Service Enumeration C# .NET Assembly☆60Updated 3 years ago
- A pair of scripts to import session and local group information that has been collected from alternate data sources into BloodHound's Neo…☆19Updated 2 years ago
- Firebase Domain Front Code☆21Updated 3 years ago
- ☆37Updated 3 years ago
- ☆41Updated 9 months ago
- BloodHound Cypher Queries Ported to a Jupyter Notebook☆53Updated 4 years ago
- Continuous kerberoast monitor☆44Updated last year
- Active DIrectory Lab for Pentesting Practice☆24Updated 2 years ago
- Resource links (video, slides & code) for my conference talks | presentations | workshops☆13Updated 3 weeks ago
- ☆41Updated 2 years ago
- Building ActiveDirectory Lab for practicing various attack vectors used during Red Team engagement.☆36Updated 4 years ago
- Ansible role to deploy RedELK server☆18Updated last year
- Repository for LNK stuff☆29Updated 2 years ago
- Convert Empire profiles to Apache mod_rewrite scripts☆27Updated 5 years ago
- Log converter from CS log to Ghostwriter CSV☆29Updated 4 years ago
- A simple command line program to help defender test their detections for network beacon patterns and domain fronting☆67Updated 2 years ago
- Reproducible and extensible BloodHound playbooks☆42Updated 5 years ago