rj-chap / ransomware_tips
Random tips and tricks RE: ransomware
☆14Updated 3 years ago
Alternatives and similar repositories for ransomware_tips:
Users that are interested in ransomware_tips are comparing it to the libraries listed below
- ☆20Updated last year
- An experimental script to perform bulk parsing of arbitrary file features with YARA and console logging.☆21Updated 2 years ago
- Notes from my "Implementing a Kick-Butt Training Program: Blue Team GO!" talk☆12Updated 5 years ago
- PowerShell 'Hero': scripts for DFIR and automation with a PowerShell menu example.☆36Updated last year
- General Content☆21Updated 6 months ago
- ☆40Updated 3 years ago
- Threat Box Assessment Tool☆19Updated 3 years ago
- ☆45Updated last week
- Cumulonimbus-UAL_Extractor is a PowerShell based tool created by the Tesorion CERT team to help gather the Unified Audit Logging out of a…☆18Updated last year
- ☆28Updated 4 years ago
- Microsoft GPO Readiness Lateral Movement Detection Tool☆16Updated 2 years ago
- Repo with supporting material for the talk titled "Cracking the Beacon: Automating the extraction of implant configurations"☆11Updated 2 years ago
- ☆26Updated 3 years ago
- CSIRT Jump Bag☆27Updated 8 months ago
- This repository aims to collect and document indicators from the different C2's listed in the C2-Matrix☆72Updated 2 years ago
- ☆19Updated 3 years ago
- Supporting materials for my "Intelligence-Led Adversarial Threat Modelling with VECTR" workshop☆57Updated this week
- gundog - guided hunting in Microsoft Defender☆52Updated 3 years ago
- Azure function to insert MISP data in to Azure Sentinel☆31Updated 2 years ago
- A script designed to test passwords against user accounts within an Active Directory environment, offering customizable Account Lockout T…☆14Updated last year
- Track progress and keep notes while working through likethecoins' CTI Self Study Plan☆28Updated 2 years ago
- An exercise to practice deobfuscating PowerShell Scripts.☆28Updated last year
- PS-TrustedDocuments: PowerShell script to handle information on trusted documents for Microsoft Office☆34Updated last year
- Random notes collected on the intertubes relating to DFIR☆32Updated last year
- A preconfigured Windows-based system designed for rapid forensic investigations in both Azure and AWS.☆37Updated 9 months ago
- ☆40Updated last year
- ☆34Updated 10 months ago
- A tool to display Windows Event logs as they happen.☆12Updated last year
- A collection of searches, interesting events and tables on Crowdstrike Splunk.☆29Updated 3 years ago