tsale / Threat-Intelligence-Playbooks
High-level Threat Intelligence playbooks
☆16Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for Threat-Intelligence-Playbooks
- Library of threat hunts to get any user started!☆40Updated 4 years ago
- Threat Box Assessment Tool☆19Updated 3 years ago
- Supporting materials for my "Intelligence-Led Adversarial Threat Modelling with VECTR" workshop☆56Updated last week
- Scripts and tools accompanying HP Threat Research blog posts and reports.☆49Updated 7 months ago
- An experimental script to perform bulk parsing of arbitrary file features with YARA and console logging.☆21Updated 2 years ago
- Rhaegal is a tool written in Python 3 used to scan Windows Event Logs for suspicious logs. Rhaegal uses custom rule format to detect sus…☆39Updated last year
- Random tips and tricks RE: ransomware☆14Updated 3 years ago
- Jupyter Notebooks for Cyber Threat Intelligence☆35Updated last year
- A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.☆39Updated 2 years ago
- ☆41Updated 7 months ago
- ☆29Updated 3 years ago
- Cyber Threats Detection Rules☆13Updated 2 months ago
- A collection of Terraform and Ansible scripts that automatically (and quickly) deploys a small Velociraptor R&D lab.☆20Updated 3 years ago
- Get-MiniTimeline - Triage Collection and Timeline Generation w/ KAPE☆26Updated 5 months ago
- BlueSploit is a DFIR framework with the main purpose being to quickly capture artifacts for later review.☆32Updated 4 years ago
- my MSTICpy practice and custom tools repository☆11Updated 2 weeks ago
- Hunt malware with Volatility☆47Updated 6 months ago
- ShellSweeping the evil.☆52Updated 5 months ago
- ☆25Updated 3 years ago
- Publicly shareable windows event log message data☆27Updated 4 years ago
- Random notes collected on the intertubes relating to DFIR☆32Updated last year
- Track progress and keep notes while working through likethecoins' CTI Self Study Plan☆28Updated 2 years ago
- ☆19Updated last year
- ☆34Updated last year
- Notes from my "Implementing a Kick-Butt Training Program: Blue Team GO!" talk☆12Updated 5 years ago
- Threat Hunter's Knowledge Base☆22Updated 2 years ago
- PowerShell 'Hero': scripts for DFIR and automation with a PowerShell menu example.☆35Updated last year
- A list of Mitre Caldera compatible emulation-plans☆14Updated 3 years ago
- A completely unsupported set of scripts used in SANS FOR572, Advanced Network Forensics and Analysis☆23Updated 4 months ago