heshamelgebaly's starred repositories
ThreatHunter-Playbook
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
awesome-forensics
⭐️ A curated list of awesome forensic analysis tools and resources
velociraptor
Digging Deeper....
APTSimulator
A toolset to make a system look as if it was the victim of an APT attack
sandbox-attacksurface-analysis-tools
Set of tools to analyze Windows sandboxes for exposed attack surface.
DumpsterFire
"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.
Offensive-Resources
A Huge Learning Resources with Labs For Offensive Security Players
ircapabilities
Incident Response Hierarchy of Needs
Python-Honeypot
OWASP Honeypot, Automated Deception Framework.
resilient-community-apps
Source code for IBM SOAR Apps that are available on our App Exchange
Sigma-Rule-Repository
Sigma Detection Rule Repository
threatconnect-playbooks
Community driven repository of Playbooks and Apps for ThreatConnect.
QRCE-Rules
These are open source rules that can be utilized with QRadar to detect various types of threats in the environment.
Client-GPOs
GPOs for client systems
resilient-scripts
Example scripts and rules for use in Resilient playbooks.
awesome-forensics
A curated list of awesome forensic analysis tools and resources