bigbrobro's repositories

api-firewall

Fast and light-weight API proxy firewall for request and response validation by OpenAPI specs.

Language:GoLicense:MPL-2.0Stargazers:0Issues:0Issues:0

APTLab-Analysis

Loading provenance graph from a set of CSV files

Language:PythonStargazers:0Issues:0Issues:0

attack-flow

Attack Flow helps executives, SOC managers, and defenders easily understand how attackers compose ATT&CK techniques into attacks by developing a representation of attack flows, modeling attack flows for a small corpus of incidents, and creating visualization tools to display attack flows.

License:Apache-2.0Stargazers:0Issues:0Issues:0

Attack_Code

文章 Attack Code 的详细全文 希望是一篇不错的云安全入门材料

Stargazers:0Issues:0Issues:0

backdoor_detection

This is a project used for detecting backdoors at different levels.

Language:PythonStargazers:0Issues:0Issues:0

bloodyAD

BloodyAD is an Active Directory Privilege Escalation Framework

Language:PythonLicense:MITStargazers:0Issues:0Issues:0

blue-teaming-with-kql

Repository with Sample KQL Query examples for Threat Hunting

License:MITStargazers:0Issues:0Issues:0

EasyPen

EasyPen is a GUI program which helps pentesters do information gathering, vulnerability scan and exploitation

Stargazers:0Issues:0Issues:0

ee-outliers

Open-source framework to detect outliers in Elasticsearch events

License:GPL-3.0Stargazers:0Issues:0Issues:0

fastjsonVul

fastjson 80 远程代码执行漏洞复现

Stargazers:0Issues:0Issues:0

gotestwaf

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Language:GoLicense:MITStargazers:0Issues:0Issues:0

kestrel-huntbook

This repository hosts community contributed Kestrel huntflows (.hf) and huntbooks (.ipynb)

Language:Jupyter NotebookLicense:NOASSERTIONStargazers:0Issues:0Issues:0

kestrel-lang

Kestrel threat hunting language: building reusable, composable, and shareable huntflows across different data sources and threat intel.

License:Apache-2.0Stargazers:0Issues:0Issues:0

Knowledge-enhanced-Attack-Graph

AttacKG: Constructing Knowledge-enhanced Attack Graphs from Cyber Threat Intelligence Reports

Language:Jupyter NotebookLicense:MITStargazers:0Issues:0Issues:0

laurel

Transform Linux Audit logs for SIEM usage

Language:RustLicense:GPL-3.0Stargazers:0Issues:0Issues:0
Language:RustLicense:Apache-2.0Stargazers:0Issues:0Issues:0

Palantir

PalanTír: Optimizing Attack Provenance with Hardware-enhanced System Observability, ACM CCS'22

License:GPL-3.0Stargazers:0Issues:0Issues:0

recon.cloud-cli

A bash script for scanning AWS public cloud footprint and getting suddomains, service name, cname and region from recon.cloud

License:UnlicenseStargazers:0Issues:0Issues:0
Language:JavaScriptLicense:BSD-3-ClauseStargazers:0Issues:0Issues:0

rengine

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.

Language:JavaScriptLicense:GPL-3.0Stargazers:0Issues:0Issues:0

rita

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Language:GoLicense:GPL-3.0Stargazers:0Issues:0Issues:0

Sandman

Sandman is a NTP based backdoor for red team engagements in hardened networks.

License:BSD-2-ClauseStargazers:0Issues:0Issues:0

siembol

An open-source, real-time Security Information & Event Management tool based on big data technologies, providing a scalable, advanced security analytics framework.

Language:JavaLicense:Apache-2.0Stargazers:0Issues:0Issues:0

SIGMA-detection-rules

Set of SIGMA rules (>250) mapped to MITRE Att@k tactic and techniques

Stargazers:0Issues:0Issues:0

SPADE

SPADE: Support for Provenance Auditing in Distributed Environments

License:GPL-3.0Stargazers:0Issues:0Issues:0
License:Apache-2.0Stargazers:0Issues:0Issues:0

StratosphereLinuxIPS

Slips, a free software behavioral Python intrusion prevention system (IDS/IPS) that uses machine learning to detect malicious behaviors in the network traffic. Stratosphere Laboratory, AIC, FEL, CVUT in Prague.

Language:PythonLicense:NOASSERTIONStargazers:0Issues:0Issues:0

stratus-red-team

:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud

Language:GoLicense:Apache-2.0Stargazers:0Issues:0Issues:0

SysmonQuiet

RDLL for Cobalt Strike beacon to silence sysmon process

License:Apache-2.0Stargazers:0Issues:0Issues:0

Threat-Hunting-and-Detection

Repository for threat hunting and detection queries, tools, etc.

License:BSD-3-ClauseStargazers:0Issues:0Issues:0