sud0woodo / Urgent11-Suricata-LUA-scripts
Suricata LUA scripts to detect CVE-2019-12255, CVE-2019-12256, CVE-2019-12258, and CVE-2019-12260
☆19Updated 5 years ago
Alternatives and similar repositories for Urgent11-Suricata-LUA-scripts:
Users that are interested in Urgent11-Suricata-LUA-scripts are comparing it to the libraries listed below
- Detecting PowerShell Empire, Metasploit Meterpreter and Cobalt Strike agents by payload size sequence analysis and host correlation☆15Updated 6 years ago
- Automate SSH communication with firewalls, switches, etc.☆26Updated 6 years ago
- Impacket is a collection of Python classes for working with network protocols.☆17Updated 4 years ago
- Apache Module Backdoor (PoC)☆48Updated 5 years ago
- Is this IP a C2 server?☆28Updated 4 years ago
- POC exploit code for CVE-2020-1048(PrintDemon)☆14Updated 4 years ago
- Remote process dumping automation. Use it to dump Windows credentials remotely and extract clear text with Mimikatz offline☆35Updated 5 years ago
- ssdeep cluster analysis for malware files☆31Updated 4 years ago
- ☆24Updated 4 years ago
- Everything related to Cobalt Strike☆15Updated 5 years ago
- This is a group of tools that I was planning on releasing During Derbycon 2019 talk if it was accepted or with a blogpost if not.☆43Updated 3 years ago
- CVE2020-0796 SMBv3 RCE☆61Updated 4 years ago
- Python script to detect bluekeep vulnerability (CVE-2019-0708) with TLS/SSL and x509 support☆27Updated 5 years ago
- Experiments on the Windows Internals☆30Updated 5 years ago
- Convert the loot directory of ntlmrelayx into an enum4linux like output☆21Updated 4 years ago
- Work in Progress repo☆14Updated 5 years ago
- CVE-2020-8950 AMD User Experience Program Launcher from Radeon Software Privilege Escalation ( FileWrite eop)☆28Updated 4 years ago
- Remove individual lines from Windows Event Viewer Log (EVT) files☆44Updated 3 years ago
- Community maintained list of most popular HIPS service and process names on a Windows Platform.☆43Updated 2 years ago
- Tool to test for existence of CVE-2020-8218☆22Updated 4 years ago
- various slides and presentations I've worked on☆18Updated 11 months ago
- Some talks about security☆13Updated 4 years ago
- ☆31Updated 4 years ago
- Tweettioc Splunk App☆20Updated 4 years ago
- Malware samples observed in the wild from time to time☆12Updated 5 years ago
- BloodHound Cypher Queries Ported to a Jupyter Notebook☆53Updated 4 years ago
- cobalt strike stuff I have gathered from around github☆31Updated 7 years ago
- A rogue DNS detector☆23Updated last year
- Python3 Metasploit automation library☆21Updated 2 years ago
- POC for CVE-2020-10665 Docker Desktop Local Privilege Escalation☆53Updated 4 years ago