Purple Team Security
☆74Mar 24, 2022Updated 4 years ago
Alternatives and similar repositories for Hornets-Nest
Users that are interested in Hornets-Nest are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Bunch of honey related items that spoof/decoy powersploit functions.☆17Apr 23, 2020Updated 6 years ago
- Lateral Movement graph for Azure Active Directory☆127Dec 8, 2022Updated 3 years ago
- ☆164Feb 13, 2020Updated 6 years ago
- Create a Run registry key with direct system calls. Inspired by @Cneelis's Dumpert and SharpHide.☆78Feb 27, 2020Updated 6 years ago
- BloodHound Cypher Queries Ported to a Jupyter Notebook☆53Jun 20, 2020Updated 6 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Automate AV evasion by calling AMSI☆87May 31, 2023Updated 3 years ago
- IOCPARSER.COM is a Fast and Reliable service that enables you to extract IOCs and intelligence from different data sources.☆36Jan 20, 2022Updated 4 years ago
- A Splunk app that will rotate between dashboards on a frequency; useful for displaying content on informational big screens.☆13Mar 9, 2022Updated 4 years ago
- This repository contains the research and components of our research into using Sigma for AWS Incident Response.☆35Jul 12, 2023Updated 3 years ago
- PowerShell 'Hero': scripts for DFIR and automation with a PowerShell menu example.☆37Jul 11, 2023Updated 3 years ago
- ☆56May 13, 2020Updated 6 years ago
- Protect your servers with a secret header☆28Jun 12, 2020Updated 6 years ago
- Compilation of resources to help with Adversary Simulation automation harness☆99Aug 7, 2020Updated 6 years ago
- Automated, extensible toolset that runs cypher queries against Bloodhound's Neo4j backend and saves output to spreadsheets.☆256Jul 29, 2021Updated 5 years ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- macOS Artifact Intelligence Tool☆13Apr 30, 2019Updated 7 years ago
- A PowerShell script to prevent Sysmon from writing its events☆16Apr 23, 2020Updated 6 years ago
- A pair of scripts to import session and local group information that has been collected from alternate data sources into BloodHound's Neo…☆21Aug 29, 2022Updated 3 years ago
- Red Team Operator: Malware Development Essentials Course☆101Jun 18, 2020Updated 6 years ago
- Threat Box Assessment Tool☆20Mar 5, 2026Updated 5 months ago
- A simple proof of concept for detecting use of Cobalt Strike's execute-assembly☆59Apr 1, 2022Updated 4 years ago
- Iterative AD discovery toolkit for offensive operations☆84Mar 16, 2020Updated 6 years ago
- Collection of tools that reflect the network dimension into Bloodhound's data☆452Oct 19, 2022Updated 3 years ago
- This repo contains code of JScript .NET which can be used as alternative to csc.exe to run potentially malicious code, which ships in all…☆12Nov 8, 2019Updated 6 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Rip Raw is a small tool to analyse the memory of compromised Linux systems.☆133Jan 31, 2022Updated 4 years ago
- A collection of scripts for dealing with Cobalt Strike beacons in Python☆168Jan 5, 2021Updated 5 years ago
- Assist analyst and threat hunters to understand Windows authentication logs and to analyze brutforce scenarios.☆21Jul 1, 2023Updated 3 years ago
- A command-line tool for parsing Windows Event Logs and importing the results into Elasticsearch.☆88Jun 2, 2026Updated 2 months ago
- ACT documentation repo☆16May 22, 2024Updated 2 years ago
- ☆18Sep 14, 2023Updated 2 years ago
- A collection of searches, interesting events and tables on Crowdstrike Splunk.☆30Mar 2, 2021Updated 5 years ago
- Using DInvoke to patch AMSI.dll in order to bypass AMSI detections triggered when loading .NET tradecraft via Assembly.Load().☆216Mar 5, 2020Updated 6 years ago
- A module for CME that spiders across a domain.☆35Jul 15, 2022Updated 4 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Identify the attack paths in BloodHound breaking your AD tiering☆328Nov 6, 2022Updated 3 years ago
- Mindmap/CheatSheet for eLearnSecurity-PTPv5☆10Jun 18, 2020Updated 6 years ago
- Misc Threat Hunting Resources☆376Jan 26, 2023Updated 3 years ago
- Kerberoast Detection Script☆31Oct 31, 2024Updated last year
- ☆99Feb 16, 2021Updated 5 years ago
- Active Directory Purple Team Playbook☆117May 8, 2023Updated 3 years ago
- Converts Sigma detection rules to a Splunk alert configuration.☆117May 18, 2020Updated 6 years ago