medtemo's repositories

guacamole-docker-compose

Guacamole with docker-compose using PostgreSQL, nginx with SSL (self-signed)

Language:ShellLicense:GPL-3.0Stargazers:1Issues:0Issues:0

threathunting-spl

Splunk code (SPL) for serious threat hunters and detection engineers.

Stargazers:1Issues:0Issues:0

ansible-splunk-playbook

Install a full Splunk Enterprise Cluster or Universal forwarder using an ansible playbook

Language:ShellStargazers:0Issues:0Issues:0

atomic-red-team

Small and highly portable detection tests based on MITRE's ATT&CK.

Language:PowerShellLicense:MITStargazers:0Issues:1Issues:0

awesome-threat-detection

A curated list of awesome threat detection and hunting resources

Stargazers:0Issues:1Issues:0

chainsaw

Rapidly Search and Hunt through Windows Forensic Artefacts

License:GPL-3.0Stargazers:0Issues:0Issues:0

CyberThreatHunting

A collection of resources for Threat Hunters

Language:PythonLicense:GPL-3.0Stargazers:0Issues:1Issues:0

DFIRMindMaps

A repository of DFIR-related Mind Maps geared towards the visual learners!

License:MITStargazers:0Issues:0Issues:0

Event-Forwarding-Guidance

Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding. #nsacyber

License:NOASSERTIONStargazers:0Issues:0Issues:0

EvilClippy

A cross-platform assistant for creating malicious MS Office documents. Can hide VBA macros, stomp VBA code (via P-Code) and confuse macro analysis tools. Runs on Linux, OSX and Windows.

Language:C#Stargazers:0Issues:1Issues:0

EVTX-to-MITRE-Attack

Set of EVTX samples (>170) mapped to MITRE Att@k tactic and techniques to measure your SIEM coverage or developed new use cases.

Stargazers:0Issues:0Issues:0

hollows_hunter

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).

License:BSD-2-ClauseStargazers:0Issues:0Issues:0

Incident-Response-with-Threat-Intelligence

Incident Response with Threat Intelligence, published by Packt

Language:YARALicense:MITStargazers:0Issues:0Issues:0

Kansa

A Powershell incident response framework

Language:PowerShellLicense:Apache-2.0Stargazers:0Issues:1Issues:0

koadic

Koadic C3 COM Command & Control - JScript RAT

Language:PythonLicense:Apache-2.0Stargazers:0Issues:1Issues:0

LOLBAS

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

Language:XSLTStargazers:0Issues:1Issues:0

malware-persistence

Collection of malware persistence and hunting information. Be a persistent persistence hunter!

License:CC-BY-SA-4.0Stargazers:0Issues:1Issues:0

Microsoft-eventlog-mindmap

Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...

License:BSD-2-ClauseStargazers:0Issues:0Issues:0

osctrl

Fast and efficient osquery management

License:MITStargazers:0Issues:0Issues:0

osq-ext-bin

Extension to osquery windows that enhances it with real-time telemetry, log monitoring and other endpoint data collection

Language:PowerShellLicense:NOASSERTIONStargazers:0Issues:1Issues:0

OSSEM-DM

OSSEM Detection Model

License:MITStargazers:0Issues:0Issues:0
Language:PowerShellLicense:MITStargazers:0Issues:1Issues:0

RedTeam-Tactics-and-Techniques

Red Teaming Tactics and Techniques

Language:PowerShellStargazers:0Issues:1Issues:0

Security-Datasets

Re-play Security Events

Language:PowerShellLicense:MITStargazers:0Issues:1Issues:0

SIEM

SIEM Tactics, Techiques, and Procedures

License:GPL-3.0Stargazers:0Issues:0Issues:0

sysmon-modular

A repository of sysmon configuration modules

License:MITStargazers:0Issues:0Issues:0

VBoxHardenedLoader

VirtualBox VM detection mitigation loader

Language:CLicense:BSD-2-ClauseStargazers:0Issues:1Issues:0

VmwareHardenedLoader

Vmware Hardened VM detection mitigation loader (anti anti-vm)

Language:CLicense:MITStargazers:0Issues:1Issues:0
License:GPL-3.0Stargazers:0Issues:0Issues:0

windows_event_logging

Windows Event Forwarding subscriptions, configuration files and scripts that assist with implementing ACSC's protect publication, Technical Guidance for Windows Event Logging.

License:BSD-3-ClauseStargazers:0Issues:0Issues:0