yk's starred repositories

vulhub

Pre-Built Vulnerable Environments Based on Docker-Compose

Language:DockerfileLicense:MITStargazers:16915Issues:572Issues:177

cvemap

Navigate the CVE jungle with ease.

Language:GoLicense:MITStargazers:1521Issues:23Issues:41

API-s-for-OSINT

List of API's for gathering information about phone numbers, addresses, domains etc

BestEdrOfTheMarket

Little user-mode AV/EDR evasion lab for training & learning purposes

Language:C++License:MITStargazers:938Issues:15Issues:4

redress

Redress - A tool for analyzing stripped Go binaries

Language:GoLicense:AGPL-3.0Stargazers:887Issues:13Issues:15

Locksmith

A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.

Language:PowerShellLicense:NOASSERTIONStargazers:747Issues:13Issues:29

KubeHound

Kubernetes Attack Graph

Language:GoLicense:Apache-2.0Stargazers:695Issues:12Issues:23

raven

CI/CD Security Analyzer

Language:PythonLicense:Apache-2.0Stargazers:588Issues:10Issues:70

MasterParser

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

Language:PowerShellLicense:MITStargazers:542Issues:10Issues:4

shell-backdoor

all shell backdoor in the world

Language:HackStargazers:349Issues:5Issues:0

awskillswitch

Lambda function that streamlines containment of an AWS account compromise

Language:GoLicense:Apache-2.0Stargazers:311Issues:4Issues:0

managed-kubernetes-auditing-toolkit

All-in-one auditing toolkit for identifying common security issues in managed Kubernetes environments. Currently supports Amazon EKS.

Language:GoLicense:Apache-2.0Stargazers:259Issues:5Issues:9

AD-Canaries

The purpose of this project is to publish and maintain the deployment PowerShell script that automates deployments for Active Directory Canary objects.

Language:PowerShellLicense:MITStargazers:198Issues:4Issues:1

YAMA

Yet Another Memory Analyzer for malware detection

Language:C++License:NOASSERTIONStargazers:168Issues:12Issues:2

IndicatorOfCanary

Canary Detection

Language:PythonLicense:GPL-2.0Stargazers:157Issues:3Issues:0

SWAT

Simple Workspace Attack Tool (SWAT) is a tool for simulating malicious behavior against Google Workspace in reference to the MITRE ATT&CK framework.

Language:PythonLicense:Apache-2.0Stargazers:137Issues:3Issues:32

PowerDecode

PowerDecode is a PowerShell-based tool that allows to deobfuscate PowerShell scripts obfuscated across multiple layers. The tool performs code dynamic analysis, extracting malware hosting URLs and checking http response.It can also detect if the malware attempts to inject shellcode into memory.

Language:PowerShellLicense:GPL-3.0Stargazers:129Issues:3Issues:2

Monocle

Tooling backed by an LLM for performing natural language searches against compiled target binaries. Search for encryption logic, password strings, vulnerabilities, etc.

Language:PythonLicense:GPL-3.0Stargazers:127Issues:7Issues:0

RMML

A list of RMMs designed to be used in automation to build alerts

Language:PythonLicense:MITStargazers:99Issues:5Issues:2

YARA_Detection_Engineering

Detection Engineering with YARA

DefenderHarvester

Expose a lot of MDE telemetry that is not easily accessible in any searchable form

Language:GoLicense:MITStargazers:79Issues:2Issues:2

SigmAIQ

A pySigma wrapper and langchain toolkit for automatic rule creation/translation

Language:PythonLicense:LGPL-2.1Stargazers:60Issues:2Issues:0

MetadataPlus

A tool to use novel locations to extract metadata from Office documents.

Language:C#License:Apache-2.0Stargazers:57Issues:8Issues:1

machofile

machofile is a module to parse Mach-O binary files

Language:PythonLicense:MITStargazers:47Issues:3Issues:5

Magnet-RESPONSE-PowerShell

PowerShell scripts for running Magnet RESPONSE forensic collection tool in large enterprises.

Language:PowerShellLicense:MITStargazers:20Issues:1Issues:0

parseusbs

Parses USB connection artifacts from offline Registry hives

Language:PythonLicense:GPL-3.0Stargazers:16Issues:2Issues:0

ccl-segb

Module(s) related to reading SEGB (fka "Biome") data from iOS, mascOS, etc.

Language:PythonLicense:MITStargazers:13Issues:4Issues:0