rkovar / sunburstlookups
Quick lookup files for SUNBURST Backdoor
☆12Updated 4 years ago
Alternatives and similar repositories for sunburstlookups:
Users that are interested in sunburstlookups are comparing it to the libraries listed below
- A completely unsupported set of scripts used in SANS FOR572, Advanced Network Forensics and Analysis☆26Updated 4 months ago
- Python command line tool used for generating GIAC Certification indexes.☆25Updated last year
- ☆30Updated 6 years ago
- Tool used to perform threat intelligence against packet data☆35Updated 2 months ago
- Threat Hunter's Knowledge Base☆22Updated 3 years ago
- My Jupyter Notebooks☆36Updated last month
- The project was moved here https://github.com/atomic-threat-coverage/atomic-threat-coverage☆24Updated 5 years ago
- CSIRT Jump Bag☆26Updated 11 months ago
- Powershell Scripts to work on Crowdstrike Falcon that pull back raw data relevant to forensic investigation☆22Updated 4 months ago
- Use DNS to hunt for threats including DGAs☆15Updated 9 years ago
- Incident response teams usually working on the offline data, collecting the evidence, then analyze the data☆44Updated 3 years ago
- PowerShell Memory Pulling script☆19Updated 10 years ago
- ☆77Updated 5 years ago
- Splunk App to assist Sysmon Threat Hunting☆38Updated 8 years ago
- incident response scripts☆19Updated 6 years ago
- Volatility plugins developed and maintained by the community☆21Updated 7 months ago
- ☆34Updated 4 years ago
- Dashboards for conducting forensic investigation using windows events in Kibana☆17Updated 6 years ago
- Recon Hunt Queries☆77Updated 3 years ago
- The Intelligent Process Lifecycle of Active Cyber Defenders☆31Updated 2 years ago
- Slides and Other Resources from my latest Talks and Presentations☆24Updated 4 years ago
- Quick script to build host or investigation timelines using Carbon Black Response☆12Updated 6 years ago
- Powershell Functions to interact with TheHive-Project☆10Updated 5 years ago
- Use Terraform to Provision Your Own Cloud-Based Remote Browsing Workstation☆25Updated 11 months ago
- Corelight@Home script☆41Updated last year
- Cumulonimbus-UAL_Extractor is a PowerShell based tool created by the Tesorion CERT team to help gather the Unified Audit Logging out of a…☆19Updated last year
- A collection of hunting and blue team scripts. Mostly others, some my own.☆38Updated 2 years ago
- PSAttck is a light-weight framework for the MITRE ATT&CK Framework.☆38Updated 3 years ago
- Open source training materials for law-enforcement and organisations interested in DFIR.☆55Updated 3 months ago
- Cyber Analytics Platform and Examination System (CAPES) Project Page☆14Updated 3 years ago