Mehmet E.'s repositories
blueteam_homelabs
Great List of Resources to Build an Enterprise Grade Home Lab
DefensiveSysmon
Repository for Defensive applications of Windows Sysmon
SPEED-SIEM-Use-Case-Framework
Repository for SPEED SIEM Use Case Framework
alerting-detection-strategy-framework
A framework for developing alerting and detection strategies for incident response.
bind9_logparse_stat
A simple frequency analysis script for bind9 DNS query logs. Is able to analyze based on client IP address, DNS domain name, and DNS query type. Uses both regular expressions, and the Counter() dictionary from the Python collections module. Is written to demonstrate how useful the combination of a Counter() dictionary and regular expressions are.
hot-manchego
Macro-Enabled Excel File Generator (.xlsm) using the EPPlus Library.
adconnectdump
Dump Azure AD Connect credentials for Azure AD and Active Directory
APT-Lab-Terraform
Purple Teaming Attack & Hunt Lab - Terraform
at-ps
Adversary Tactics - PowerShell Training
atomic-red-team
Small and highly portable detection tests based on MITRE's ATT&CK.
cryptofile
Encrypt or decrypt files using AES-256 or AES-128
cryptolocked-ng
An updated version of the cryptolocked (anti-ransomware) toolkit. Adds new features such as the hunter module.
EmbedInHTML
Embed and hide any file in an HTML file
GonnaCry
A Linux Ransomware
graphdatamap
Graph Data Map Project
leonidas
Automated Attack Simulation in the Cloud, complete with detection use cases.
malwoverview
Malwoverview is a first response tool to perform an initial and quick triage in a directory containing malware samples, specific malware sample, suspect URL and domains. Additionally, it allows to download and send samples to main online sandboxes.
pivotmap
Analyst tool for creating pivot maps of data sources
pydefenders
Home repo for documentation and links to resources
PyWare
Ransomware PoC written in python
ransomware
A POC Windows crypto-ransomware (Academic)
unfurl
Extract and Visualize Data from URLs using Unfurl
wildlogger
This is a keylogger that collects all the data and e-mail it in a set time with system information which includes device S/N and hardware specs, every button that pushed, screenshots, and copying processes.