yk's starred repositories

threatest

Threatest is a CLI and Go framework for end-to-end testing threat detection rules.

Language:GoLicense:Apache-2.0Stargazers:310Issues:0Issues:0

CyberChef

CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition

Language:JavaScriptLicense:Apache-2.0Stargazers:61Issues:0Issues:0

fauxpilot

FauxPilot - an open-source alternative to GitHub Copilot server

Language:PythonLicense:MITStargazers:14296Issues:0Issues:0

BlueHound

BlueHound - pinpoint the security issues that actually matter

Language:TypeScriptLicense:Apache-2.0Stargazers:683Issues:0Issues:0

public-pentesting-reports

A list of public penetration test reports published by several consulting firms and academic security groups.

Language:HTMLStargazers:8133Issues:0Issues:0

StratosphereLinuxIPS

Slips, a free software behavioral Python intrusion prevention system (IDS/IPS) that uses machine learning to detect malicious behaviors in the network traffic. Stratosphere Laboratory, AIC, FEL, CVUT in Prague.

Language:PythonLicense:NOASSERTIONStargazers:655Issues:0Issues:0

Hunting-Queries-Detection-Rules

KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.

Language:PythonLicense:BSD-3-ClauseStargazers:1019Issues:0Issues:0
Language:CLicense:GPL-3.0Stargazers:167Issues:0Issues:0
Language:HCLLicense:Apache-2.0Stargazers:605Issues:0Issues:0

macOS-Security-and-Privacy-Guide

Guide to securing and improving privacy on macOS

Language:PythonLicense:MITStargazers:20930Issues:0Issues:0

Events-Ripper

Project based on RegRipper, to extract add'l value/pivot points from TLN events file

Language:PerlLicense:GPL-3.0Stargazers:61Issues:0Issues:0

multithreaded-exfil-detection

A simple way of detecting multithreaded exfiltration in Zeek.

Language:ZeekLicense:BSD-3-ClauseStargazers:14Issues:0Issues:0

chepy

Chepy is a python lib/cli equivalent of the awesome CyberChef tool.

Language:PythonLicense:GPL-3.0Stargazers:855Issues:0Issues:0

it-depends

A tool to automatically build a dependency graph and Software Bill of Materials (SBOM) for packages and arbitrary source code repositories.

Language:PythonLicense:LGPL-3.0Stargazers:318Issues:0Issues:0

conti-leaks-englished

Google and deepl translated conti leaks, which is shared by a member of the conti ransomware group.

Language:Rich Text FormatStargazers:570Issues:0Issues:0

spacesiren

A honey token manager and alert system for AWS.

Language:PythonLicense:GPL-3.0Stargazers:313Issues:0Issues:0

threat-tools

Tools for simulating threats

Language:PythonLicense:GPL-3.0Stargazers:151Issues:0Issues:0
Language:PythonStargazers:157Issues:0Issues:0
Language:C#License:MITStargazers:31Issues:0Issues:0

geoipsed

Fast, inline geolocation decoration of IPv4 and IPv6 addresses written in Rust

Language:RustLicense:UnlicenseStargazers:25Issues:0Issues:0

memory-baseliner

Memory Baseliner is a script that can compare two windows memory images or perform frequency of occurrence / data stacking analysis on multiple such images

Language:PythonLicense:GPL-3.0Stargazers:44Issues:0Issues:0

PSBits

Simple (relatively) things allowing you to dig a bit deeper than usual.

Language:CLicense:UnlicenseStargazers:3003Issues:0Issues:0

FollinaExtractor

Extract payload URLs from Follina (CVE-2022-30190) docx and rtf files

Language:PythonStargazers:30Issues:0Issues:0

Kuiper

Digital Forensics Investigation Platform

Language:JavaScriptStargazers:722Issues:0Issues:0

dfir-iris-misp-timesketch

Scripts to integrate DFIR-IRIS, MISP and TimeSketch

Language:PythonLicense:AGPL-3.0Stargazers:29Issues:0Issues:0

webshell

This is a webshell open source project

Language:PHPLicense:MITStargazers:9804Issues:0Issues:0

msticpy

Microsoft Threat Intelligence Security Tools

Language:PythonLicense:NOASSERTIONStargazers:1700Issues:0Issues:0

mihari

A query aggregator for OSINT based threat hunting

Language:RubyLicense:MITStargazers:828Issues:0Issues:0

beacon-fronting

A simple command line program to help defender test their detections for network beacon patterns and domain fronting

Language:GoLicense:MITStargazers:64Issues:0Issues:0