Eric's repositories

PSPy

AWS PowerShell Python Lambda, or PSPy for short, is a simple Python 2.7 AWS Lambda function designed to execute the PowerShell binary and marshal input/output to PowerShell.

Language:PythonLicense:NOASSERTIONStargazers:24Issues:6Issues:1

TA_ETW

Splunk Technology Add-On (TA) for collecting ETW events from Windows systems

Language:C#License:NOASSERTIONStargazers:17Issues:3Issues:6

DuoPusher

Duo MFA auditing tool to test users' likelihood of approving unexpected push notifications

Language:PythonStargazers:13Issues:2Issues:0

python-urlscan

Simple python class to interface with UrlScan.io

Language:PythonStargazers:5Issues:0Issues:0

atomic-red-team

Small and highly portable detection tests based on MITRE's ATT&CK.

License:MITStargazers:1Issues:0Issues:0

sublime-rules

Sublime rules for email attack detection, prevention, and threat hunting.

Language:PythonLicense:MITStargazers:1Issues:0Issues:0

alerting-detection-strategy-framework

A framework for developing alerting and detection strategies for incident response.

License:MITStargazers:0Issues:0Issues:0

APOLLO

Apple Pattern of Life Lazy Output'er

Language:PythonLicense:NOASSERTIONStargazers:0Issues:0Issues:0

BITB

Browser In The Browser (BITB) Templates

Stargazers:0Issues:0Issues:0

cbapi-python

Carbon Black API - Python language bindings

Language:PythonLicense:NOASSERTIONStargazers:0Issues:1Issues:0

content

Demisto is now Cortex XSOAR. Automate and orchestrate your Security Operations with Cortex XSOAR's ever-growing Content Repository. Pull Requests are always welcome and highly appreciated!

Language:PythonLicense:MITStargazers:0Issues:1Issues:0

CredKing

Password spraying using AWS Lambda for IP rotation

Language:PythonStargazers:0Issues:2Issues:0

CVE-2022-22963

CVE-2022-22963 PoC

Stargazers:0Issues:0Issues:0
Language:PythonLicense:MITStargazers:0Issues:1Issues:0

detections

A home for detection content developed by the delivr.to team

Stargazers:0Issues:0Issues:0

File-Smuggling

HTML smuggling is not an evil, it can be useful

Stargazers:0Issues:0Issues:0

iLEAPP

iOS Logs, Events, And Plist Parser

Language:PythonLicense:MITStargazers:0Issues:0Issues:0

iTunes_Backup_Reader

Python 3 Script to parse out iTunes backups

License:MITStargazers:0Issues:0Issues:0

KilledProcessCanary

A canary designed to minimize the impact from certain Ransomware actors

Language:C#License:AGPL-3.0Stargazers:0Issues:1Issues:0

koadic

Koadic C3 COM Command & Control - JScript RAT

Language:PythonLicense:Apache-2.0Stargazers:0Issues:2Issues:0

LOLBAS

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

Language:XSLTStargazers:0Issues:2Issues:0
Language:PythonLicense:Apache-2.0Stargazers:0Issues:1Issues:0

Red-Team-Infrastructure-Wiki

Wiki to collect Red Team infrastructure hardening resources

License:BSD-3-ClauseStargazers:0Issues:0Issues:0

serverless-kinesis-firehose

JSON collector powered by Serverless Framework, Amazon Kinesis Firehose, Amazon S3

Language:TypeScriptStargazers:0Issues:0Issues:0

stethoscope

Personalized, user-focused recommendations for employee information security.

Language:PythonLicense:Apache-2.0Stargazers:0Issues:2Issues:0

TA-ouilookup

WireShark OUI Lookup -- Simple Splunk TA for obtaining the manufacturer for a provided MAC address

Language:PythonStargazers:0Issues:2Issues:0

unredacter

Never ever ever use pixelation as a redaction technique

Language:TypeScriptLicense:GPL-3.0Stargazers:0Issues:1Issues:0
Stargazers:0Issues:0Issues:0

windows-event-forwarding

A repository for using windows event forwarding for incident detection and response

Language:RoffLicense:NOASSERTIONStargazers:0Issues:0Issues:0