Gavin Knapp (m4nbat)

m4nbat

Geek Repo

Location:Sunny Wales

Twitter:@knappresearchlb

Github PK Tool:Github PK Tool

Gavin Knapp's repositories

KustQueryLanguage_kql

Cyber Defence related kusto queries for use in Azure Sentinel and Defender advanced hunting

Language:BatchfileStargazers:51Issues:0Issues:0

SecBlogs

Rough blogs covering CyberDefence tradecraft.

Stargazers:2Issues:0Issues:0

atomic-red-team

Small and highly portable detection tests based on MITRE's ATT&CK.

Language:PowerShellLicense:MITStargazers:1Issues:0Issues:0

Azure-Sentinel

Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Language:Jupyter NotebookLicense:MITStargazers:1Issues:0Issues:0

DefensivePowerShell

repo with scripts to query VT API via PowerShell

Language:PowerShellStargazers:1Issues:0Issues:0

Hunting-Queries-Detection-Rules

KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.

Stargazers:1Issues:0Issues:0

ioc_lists

IOC lists used for external lookups

Stargazers:1Issues:0Issues:0

m4nbat

Config files for my GitHub profile.

Stargazers:1Issues:0Issues:0

sigma

Main Rule Repository - Used by GK for SIGMA submissions

Language:PythonLicense:NOASSERTIONStargazers:1Issues:0Issues:0
Stargazers:1Issues:0Issues:0

yara_rules

Repo for YARA rules written by and me and other third party rules I find useful

Language:YARAStargazers:1Issues:0Issues:0

deepdarkCTI

Collection of Cyber Threat Intelligence sources from the deep and dark web

License:GPL-3.0Stargazers:0Issues:0Issues:0

DFIR_Scripts

Repo to hold useful DFIR scripts

Language:PowerShellStargazers:0Issues:0Issues:0

Enum

Just a simple PowerShell Enumeration Script

License:GPL-3.0Stargazers:0Issues:0Issues:0

FitnessAndNutrition

Fitness and Nutrition Programs

Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

MS-Sentinel-Content

Microsoft Sentinel Content

Stargazers:0Issues:0Issues:0

MultiOneTimePassword-CredentialProvider

Aims to improve the overall security of the Windows logon process by adding 2FA Authentication. Uses multiOTP as authentication endpoint.

Language:C++License:Apache-2.0Stargazers:0Issues:0Issues:0

OffensiveNotion

Notion as a platform for offensive operations

License:MITStargazers:0Issues:0Issues:0
Language:PowerShellStargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0
Language:ShellStargazers:0Issues:0Issues:0