Binary Defense's repositories
log4j-honeypot-flask
Internal network honeypot for detecting if an attacker or insider threat scans your network for log4j CVE-2021-44228
YaraMemoryScanner
Simple PowerShell script to enable process scanning with Yara.
beacon-fronting
A simple command line program to help defender test their detections for network beacon patterns and domain fronting
BinaryDefense.FSharp.Analyzers
Security analyzers for the FSharp (F#) language
IcedDecrypt
IcedID Decryption Tool
GhidraRustDependenciesExtractor
Ghidra script for extracting embedded Rust crate dependency strings from a compiled Rust binary
JsonWrapper
A Myriad plugin for generating statically typed lossless wrappers around JToken given a schema.
sysmon-modular
A repository of sysmon configuration modules
community-threats
A place to share attack chains for testing people, process, and technology with the entire community. The largest, public library of adversary emulation and adversary simulation plans! #ThreatThursday
glyph-hunter
Python Flask web app that checks names for potential homoglyph characteristics and reports results in json format
borat-rat-plugin-emulators
.Net Libraries (DLLs) re-written from scratch that emulate the functionality of Borat RAT for defese testing purposes
mining-pools
List of mining pool domain names for use in detection logic
OTX-Microsoft-Logic-App
Microsoft Logic App for consuming Open Threat Exchange (OTX) data in Microsoft Sentinel / Log Analytics Workspace