rapid7 / insightvm-sql-queries
InsightVM helpful SQL queries
☆59Updated this week
Related projects ⓘ
Alternatives and complementary repositories for insightvm-sql-queries
- ☆54Updated 3 years ago
- Tools for simulating threats☆178Updated last year
- Dashboard for conducting Backdoors and Breaches sessions over Zoom.☆112Updated last month
- Scripts for rapid Windows endpoint "tactical triage" and investigations with Velociraptor and KAPE☆105Updated 2 weeks ago
- Conference presentations☆47Updated last year
- Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.☆125Updated 2 years ago
- Security Scripts and Sources for daily usage.☆49Updated 3 weeks ago
- Distribution of the SANS SEC504 Windows Cheat Sheet Lab☆66Updated 4 years ago
- Backdoors & Breaches: Campaigns. These are short guides to help Incident Captains by giving them game ideas based on actual breaches.☆32Updated 11 months ago
- Repository of SentinelOne Deep Visibility queries.☆119Updated 3 years ago
- Threat Hunting Toolkit is a Swiss Army knife for threat hunting, log processing, and security-focused data science☆122Updated 3 weeks ago
- A collection of various SIEM rules relating to malware family groups.☆62Updated 5 months ago
- Notes on responding to security breaches relating to Azure AD☆96Updated 2 years ago
- ☆41Updated 6 months ago
- MITRE ATT&CK mapped queries for SentinelOne Deep Visiblity☆86Updated 3 years ago
- Repository of attack and defensive information for Business Email Compromise investigations☆230Updated 2 months ago
- A port of BHIS's Backdoors & Breaches for playingcards.io☆60Updated last year
- ☆75Updated 3 weeks ago
- Real-time Response scripts and schema☆104Updated 11 months ago
- MISP to Sentinel integration☆60Updated last week
- Microsoft 365 Advanced Hunting Queries with hotlinks that plug the query right into your tenant☆111Updated 3 months ago
- Audit Inspector is a tool for configuring and auditing Windows auditing.☆32Updated last month
- A browser extension for threat hunting that provides one UI for different SIEMs/EDRs and simplifies investigation☆75Updated 6 months ago
- Some Threat Hunting queries useful for blue teamers☆123Updated 2 years ago
- Windows Malware Investigation Scripts & Docs☆75Updated 2 weeks ago
- A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon☆193Updated 4 years ago
- Dashboard for conducting Backdoors and Breaches sessions over Zoom.☆54Updated last month
- Full of public notes and Utilities☆87Updated last week
- ☆66Updated 8 months ago