Steve's repositories

ThreatHunter-Playbook

A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns.

Language:PythonLicense:MITStargazers:12Issues:0Issues:0

AuthLogParser

AuthLogParser is a powerful DFIR tool designed specifically for analyzing Linux authentication logs, commonly known as auth.log

Language:PowerShellLicense:MITStargazers:0Issues:0Issues:0

Awesome-GPT-Agents

A curated list of GPT agents for cybersecurity

License:Apache-2.0Stargazers:0Issues:0Issues:0

AWS-SG-Analyzer

Python script to analyze and extract all Security Groups information

License:GPL-3.0Stargazers:0Issues:0Issues:0

catspin

Catspin rotates the IP address of HTTP requests making IP based blocks or slowdown measures ineffective. It is based on AWS API Gateway and deployed via AWS Cloudformation.

License:GPL-3.0Stargazers:0Issues:0Issues:0

CB-Threat-Hunting

Security operations queries and actions with CarbonBlack Response. Forked from @0xAnalyst

Language:PythonLicense:GPL-3.0Stargazers:0Issues:0Issues:0

Conferences

Conference slides

Stargazers:0Issues:0Issues:0

dissect.target

The Dissect module tying all other Dissect modules together. It provides a programming API and command line tools which allow easy access to various data sources inside disk images or file collections (a.k.a. targets).

Language:PythonLicense:AGPL-3.0Stargazers:0Issues:0Issues:0

FalconHound

FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is designed to be used in conjunction with a SIEM or other log aggregation tool.

Language:GoLicense:BSD-3-ClauseStargazers:0Issues:0Issues:0

ForensicMiner

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Stargazers:0Issues:0Issues:0

forensictools

Collection of forensic tools

Language:Inno SetupLicense:Apache-2.0Stargazers:0Issues:0Issues:0

galah

Galah: an LLM-powered web honeypot using the OpenAI API.

Language:GoLicense:Apache-2.0Stargazers:0Issues:0Issues:0

generative-ai-for-beginners

12 Lessons, Get Started Building with Generative AI 🔗 https://microsoft.github.io/generative-ai-for-beginners/

Language:Jupyter NotebookLicense:MITStargazers:0Issues:0Issues:0

god-mode-rules

God Mode Detection Rules

Language:YARALicense:Apache-2.0Stargazers:0Issues:0Issues:0

gsvsoc_cirt-playbook-battle-cards

Cyber Incident Response Team Playbook Battle Cards

License:MITStargazers:0Issues:0Issues:0

Incident-Response-Powershell

This page contains two Powershell Digital Forensics & Incident Response solutions. The first is a complete incident response script. The second is a page where all the individual incident response commands are listed.

License:BSD-3-ClauseStargazers:0Issues:0Issues:0

KQL-threat-hunting-queries

A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).

License:MITStargazers:0Issues:0Issues:0

kubernetes-for-soc

kubernetes-for-soc aims to fast-track the learning curve for SOC analysts by enabling them to swiftly grasp the essential concepts and knowledge necessary to perform their critical duties.

License:GPL-3.0Stargazers:0Issues:0Issues:0

learning-reverse-engineering

This repository contains sample programs written primarily in C and C++ for learning native code reverse engineering.

Language:CStargazers:0Issues:0Issues:0

Linux-Incident-Response

practical toolkit for cybersecurity and IT professionals. It features a detailed Linux cheatsheet for incident response

Language:ShellStargazers:0Issues:0Issues:0

MDE-DFIR-Resources

A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.

License:MITStargazers:0Issues:0Issues:0

MDEtester

MDE Tester is designed to help testing various features in Microsoft Defender for Endpoint.

License:BSD-3-ClauseStargazers:0Issues:0Issues:0
License:GPL-3.0Stargazers:0Issues:0Issues:0

NetExec

The Network Execution Tool

Language:PythonLicense:BSD-2-ClauseStargazers:0Issues:0Issues:0

privacy.sexy

Open-source tool to enforce privacy & security best-practices on Windows, macOS and Linux, because privacy is sexy

Language:TypeScriptLicense:AGPL-3.0Stargazers:0Issues:0Issues:0

ScriptSentry

ScriptSentry finds misconfigured and dangerous logon scripts.

Stargazers:0Issues:0Issues:0

SigmaToARM

Python script to convert Sigma rules to Azure ARM templates for Sentinel-as-Code deployments.

Language:PythonLicense:MITStargazers:0Issues:0Issues:0

SOAPHound

SOAPHound is a custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active Directory Web Services (ADWS) protocol.

License:GPL-3.0Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

sysmon-dfir

Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.

License:GPL-3.0Stargazers:0Issues:0Issues:0