thinkst / defending-off-the-land
Assortment of scripts and tools for our Blackhat EU 2024 talk
☆84Updated 2 months ago
Alternatives and similar repositories for defending-off-the-land:
Users that are interested in defending-off-the-land are comparing it to the libraries listed below
- Rules shared by the community from 100 Days of YARA 2025☆31Updated 2 months ago
- Baseline a Windows System against LOLBAS☆26Updated 11 months ago
- Cyber threat intelligence tool suite.☆20Updated this week
- A simple tool designed to create Atomic Red Team tests with ease.☆39Updated 3 weeks ago
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆78Updated 7 months ago
- LOLESXi is a curated compilation of binaries/scripts available in VMware ESXi that are were used to by adversaries in their intrusions. T…☆122Updated 2 months ago
- God Mode Detection Rules☆134Updated 7 months ago
- Living Off Security Tools☆45Updated 5 months ago
- The LOLBins CTI-Driven (Living-Off-the-Land Binaries Cyber Threat Intelligence Driven) is a project that aims to help cyber defenders und…☆119Updated last year
- The ultimate repository for remotely deploying Crowdstrike sensors quickly and discreetly on any other EDR platform.☆22Updated this week
- Mapping of open-source detection rules and atomic tests.☆159Updated 2 months ago
- ☆74Updated last week
- ☆91Updated this week
- 🧰 ESXi Testing Tookit is a command-line utility designed to help security teams test ESXi detections.☆72Updated this week
- Canary Hunter aims to be a quick PowerShell script to check for Common Canaries in various formats generated for free on canarytokens.org☆119Updated 2 years ago
- Silver SAML forgery tool☆49Updated last year
- Active C&C Detector☆153Updated last year
- A home for detection content developed by the delivr.to team☆68Updated 2 months ago
- ☆24Updated 2 years ago
- Tool created for Red Team to test default credentials on SSH and WinRM and then execute scripts with those credentials before the passwor…☆38Updated last year
- Providing Azure pipelines to create an infrastructure and run Atomic tests.☆51Updated last year
- Repo containing various intel-based resources such as threat research, adversary emulation/simulation plan and so on☆81Updated 11 months ago
- Slides of my public talks☆54Updated last year
- This project is an Ansible Role to execute Atomic Red Team tests against multiple machines by wrapping Invoke-AtomicRedTeam☆27Updated 9 months ago
- ☆38Updated last year
- FJTA (Forensic Journal Timeline Analyzer) is a tool that analyzes Linux filesystem (EXT4, XFS) journals (not systemd-journald), generates…☆62Updated this week
- Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations☆84Updated 8 months ago
- CarbonBlack EDR detection rules and response actions☆71Updated 6 months ago
- ☆23Updated last month
- A tool collection for filtering and visualizing logon events. Designed to help answering the "Cotton Eye Joe" question (Where did you com…☆167Updated last month