tstromberg / ttp-benchLinks
Adversary emulation for EDR/SIEM testing (macOS/Linux)
☆53Updated 2 weeks ago
Alternatives and similar repositories for ttp-bench
Users that are interested in ttp-bench are comparing it to the libraries listed below
Sorting:
- Attaché provides an emulation layer for Cloud Provider IMDS APIs☆60Updated 3 weeks ago
- A Golang library for interacting with the EPSS (Exploit Prediction Scoring System).☆30Updated 11 months ago
- Automated testing, generation & manipulation of #osquery packs☆74Updated last year
- ☆86Updated 3 weeks ago
- Lightweight macOS detection agent built on Santa’s Endpoint Security telemetry.☆101Updated last month
- ☆46Updated last year
- ☆185Updated 9 months ago
- ## Auto-archived due to inactivity. ## Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Securit…☆37Updated last year
- Golang-based SDK to CrowdStrike's APIs☆78Updated last week
- Repository to archive GCP Documentation for local use☆16Updated 11 months ago
- Clean accounts over permissions in GCP infra at scale☆71Updated 2 years ago
- Simple root privilege escalation detection using eBPF 🐝☆35Updated 3 months ago
- PEACH - a step-by-step framework for modeling and improving SaaS and PaaS tenant isolation, by managing the attack surface exposed by use…☆74Updated 3 years ago
- ☆13Updated last year
- ☆93Updated 2 months ago
- ☆37Updated 4 years ago
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆103Updated last year
- Pentester-focused Docker registry tool to enumerate and pull images☆36Updated 3 months ago
- ☆40Updated 2 months ago
- pocket guide for core detection engineering concepts☆31Updated 2 years ago
- K8s API Honeypot with Active Defense Capabilities☆44Updated 2 years ago
- A recon tool for GCP Service Account Keys that requires no permissions☆25Updated 9 months ago
- ☆115Updated 5 months ago
- ForgeArmory provides TTPs that can be used with the TTPForge (https://github.com/facebookincubator/ttpforge).☆119Updated last month
- Red team tool that emulates the SolarWinds CI compromise attack vector.☆24Updated last year
- ☆51Updated last month
- prel(iminary) is an application that temporarily assigns Google Cloud IAM Roles and includes an approval process.☆45Updated this week
- A PoC to Simulate Ransomware Attack on AWS Environment☆32Updated last year
- Fun tools around the EBS Direct API☆19Updated 4 years ago
- This terraform provider can be used to get remote code execution by injecting a dummy resource in a writeable state file.☆60Updated last year