BlueTeamOps (blueteam0ps)

blueteam0ps

Geek Repo

Location:Sydney

Github PK Tool:Github PK Tool

BlueTeamOps's repositories

memOptix

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

Language:Jupyter NotebookLicense:Apache-2.0Stargazers:93Issues:4Issues:1

AllthingsTimesketch

This repository contains helper scripts and custom configs to get the best out of Google's Timesketch project.

Language:ShellLicense:Apache-2.0Stargazers:84Issues:6Issues:7

det-eng-samples

This repository contains sample log data that were collected after running adversary simulations in Microsoft 365

License:Apache-2.0Stargazers:17Issues:1Issues:0

timesketch

Collaborative forensic timeline analysis

Language:PythonLicense:Apache-2.0Stargazers:2Issues:0Issues:0

atomic-red-team

Small and highly portable detection tests based on MITRE's ATT&CK.

Language:CLicense:MITStargazers:1Issues:0Issues:0

Azure-Sentinel-Notebooks

Interactive Azure Sentinel Notebooks provides security insights and actions to investigate anomalies and hunt for malicious behaviors.

Language:Jupyter NotebookLicense:MITStargazers:1Issues:0Issues:0

block-parser

Parser for Windows PowerShell script block logs

Language:PythonLicense:Apache-2.0Stargazers:1Issues:0Issues:0

chainsaw

Rapidly Search and Hunt through Windows Event Logs

Language:RustLicense:GPL-3.0Stargazers:1Issues:0Issues:0

Infosec_Reference

An Information Security Reference That Doesn't Suck

License:MITStargazers:1Issues:0Issues:0

LOLBAS-1

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

License:GPL-3.0Stargazers:1Issues:0Issues:0

Microsoft-Extractor-Suite

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

Language:PowerShellLicense:GPL-2.0Stargazers:1Issues:0Issues:0

plaso

Super timeline all the things

Language:PythonLicense:Apache-2.0Stargazers:1Issues:0Issues:0

tactical-lists

This repo was created to host lists that can come in handy for DFIR teams.

License:Apache-2.0Stargazers:1Issues:0Issues:0

Tools

Tools from WFA 4/e, timeline tools, etc.

Language:PerlStargazers:1Issues:0Issues:0

bulk_extractor

This is the development tree. Production downloads are at:

Language:C++License:NOASSERTIONStargazers:0Issues:0Issues:0

CyLR-1

CyLR - Live Response Collection Tool

Language:C#License:GPL-3.0Stargazers:0Issues:0Issues:0
License:GPL-3.0Stargazers:0Issues:0Issues:0

elasticsearch-plaso-pipelines

Elasticsearch pipelines for processing and enriching plaso data

Language:MakefileLicense:Apache-2.0Stargazers:0Issues:0Issues:0

hayabusa

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

License:GPL-3.0Stargazers:0Issues:0Issues:0

invoke-atomicredteam

Invoke-AtomicRedTeam is a PowerShell module to execute tests as defined in the [atomics folder](https://github.com/redcanaryco/atomic-red-team/tree/master/atomics) of Red Canary's Atomic Red Team project.

License:MITStargazers:0Issues:0Issues:0

plaso_filters

Scripts to facilitate filtering with Plaso

Stargazers:0Issues:0Issues:0

Public

Collection of scripts provided for public use

Language:ShellLicense:CC0-1.0Stargazers:0Issues:0Issues:0

RegRipper3.0

RegRipper3.0

License:NOASSERTIONStargazers:0Issues:0Issues:0

repo-template

A template for creating new repositories in the @orbitdb organization

License:MITStargazers:0Issues:0Issues:0

rhq

Recon Hunt Queries

Stargazers:0Issues:0Issues:0

Security-Datasets

Re-play Security Events

License:MITStargazers:0Issues:0Issues:0

sigma

Generic Signature Format for SIEM Systems

Language:PythonLicense:NOASSERTIONStargazers:0Issues:0Issues:0

sigma-cli

The Sigma command line interface based on pySigma

Language:PythonStargazers:0Issues:0Issues:0

signature-base

YARA signature and IOC database for my scanners and tools

Language:YARALicense:NOASSERTIONStargazers:0Issues:0Issues:0

SuperMem

A python script developed to process Windows memory images based on triage type.

Language:PythonLicense:MITStargazers:0Issues:0Issues:0