thinkst / defending-off-the-land
Assortment of scripts and tools for our Blackhat EU 2024 talk
☆17Updated 2 weeks ago
Alternatives and similar repositories for defending-off-the-land:
Users that are interested in defending-off-the-land are comparing it to the libraries listed below
- ☆10Updated 6 months ago
- Dont Gamble with Risk☆14Updated 11 months ago
- Scan files for potential threats while leveraging AMSI (Antimalware Scan Interface) and Windows Defender. By isolating malicious content.☆13Updated last month
- Scans a list of raccoon servers from Tria.ge and extracts the config☆15Updated last year
- ☆14Updated 9 months ago
- Freyja is a Golang, Purple Team agent that compiles into Windows, Linux and macOS x64 executables.☆42Updated 3 months ago
- A list of IOCs applicable to PoshC2☆24Updated 4 years ago
- ☆14Updated last year
- FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.☆50Updated 11 months ago
- Crowdstrike Falcon Host script for iterating through instances to get alert and other relevant data☆13Updated 5 years ago
- ☆10Updated 4 years ago
- Recreation of most of the Raccoon Infostealer's functionality, true to threat intelligence, for safe testing in organizational environmen…☆16Updated last year
- Machine learning enabled dropper☆26Updated last year
- Continuous kerberoast monitor☆44Updated last year
- Tools for playing w/ CobaltStrike config - extractin, detection, processing, etc...☆27Updated last year
- ☆15Updated 3 years ago
- Automatically spider the result set of a Censys/Shodan search and download all files where the file name or folder path matches a regex.☆27Updated last year
- HoneyZure is a honeypot tool specifically designed for Azure environments, fully provisioned through Terraform. It leverages a Log Analyt…☆16Updated 8 months ago
- C# User Simulation☆32Updated 2 years ago
- Threat Mitigation Strategies☆25Updated last year
- Offensive Research Guide to Help Defense Improve Detection☆30Updated 2 years ago
- Living off the False Positive!☆33Updated 3 weeks ago
- Providing Azure pipelines to create an infrastructure and run Atomic tests.☆50Updated last year
- Reproducible and extensible BloodHound playbooks☆42Updated 5 years ago
- Creates an ATT&CK Navigator map of an Adversary Emulation Plan☆17Updated 3 years ago
- ☆20Updated last year
- Low budget VirusTotal Intelligence Cosplay☆20Updated 3 years ago
- Tools that trigger False Positive AV alerts☆44Updated last month
- Vagrant Files to create a Virtualbox VM for Malware Analysis☆13Updated 3 years ago
- PS-TrustedDocuments: PowerShell script to handle information on trusted documents for Microsoft Office☆34Updated last year