BlueTeamOps's repositories
AllthingsTimesketch
This repository contains helper scripts and custom configs to get the best out of Google's Timesketch project.
det-eng-samples
This repository contains sample log data that were collected after running adversary simulations in Microsoft 365
timesketch
Collaborative forensic timeline analysis
atomic-red-team
Small and highly portable detection tests based on MITRE's ATT&CK.
Azure-Sentinel-Notebooks
Interactive Azure Sentinel Notebooks provides security insights and actions to investigate anomalies and hunt for malicious behaviors.
block-parser
Parser for Windows PowerShell script block logs
Infosec_Reference
An Information Security Reference That Doesn't Suck
Microsoft-Extractor-Suite
A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.
tactical-lists
This repo was created to host lists that can come in handy for DFIR teams.
bulk_extractor
This is the development tree. Production downloads are at:
CyLR-1
CyLR - Live Response Collection Tool
elasticsearch-plaso-pipelines
Elasticsearch pipelines for processing and enriching plaso data
hayabusa
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
invoke-atomicredteam
Invoke-AtomicRedTeam is a PowerShell module to execute tests as defined in the [atomics folder](https://github.com/redcanaryco/atomic-red-team/tree/master/atomics) of Red Canary's Atomic Red Team project.
plaso_filters
Scripts to facilitate filtering with Plaso
Public
Collection of scripts provided for public use
RegRipper3.0
RegRipper3.0
repo-template
A template for creating new repositories in the @orbitdb organization
rhq
Recon Hunt Queries
Security-Datasets
Re-play Security Events
sigma
Generic Signature Format for SIEM Systems
sigma-cli
The Sigma command line interface based on pySigma
signature-base
YARA signature and IOC database for my scanners and tools
SuperMem
A python script developed to process Windows memory images based on triage type.