Stars
Atomic Purple Team Framework and Lifecycle
Building environments to replicate small networks and deploy applications
The Infosec Community Definitive Guide to Jupyter Notebooks
Automated Script to capture forensic evidences (logs) from an Windows EndPoint.
This is the One Stop place where you can several Detection Rules which can help you to kick start your journey on SIEM, SOC work.
Collection of example YARA-L rules for use within Google Security Operations
Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques
A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
A Python package to search & delete messages from mailboxes in Office 365 using Microsoft Graph API
Tsunami is a general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence.
The FLARE team's open-source tool to identify capabilities in executable files.
JSON DataSet for macOS mapped to MITRE ATT&CK Tactics.
CONVEX is a group of CTFs that are independently deployable into participant Azure environments.
A collection of scripts for assessing Microsoft Azure security
wsb-detect enables you to detect if you are running in Windows Sandbox ("WSB")
A tool to perform Kerberos pre-auth bruteforcing
Offensive Software Exploitation Course
A Splunk App containing Sigma detection rules, which can be updated from a Git repository.
Repository with pre-built Sigma rules for Elastic SIEM
Ansible playbook to convert Sigma rules to ElastAlert rules
Sparrow.ps1 was created by CISA's Cloud Forensics team to help detect possible compromised accounts and applications in the Azure/m365 environment.
Malware samples, analysis exercises and other interesting resources.