-
-
AIL-framework Public
Forked from CIRCL/AIL-frameworkAnalysis Information Leak framework. Project moved to https://github.com/ail-project
Python GNU Affero General Public License v3.0 UpdatedFeb 15, 2024 -
APT_CyberCriminal_Campagin_Collections Public
Forked from CyberMonitor/APT_CyberCriminal_Campagin_CollectionsAPT & CyberCriminal Campaign Collection
YARA UpdatedJan 30, 2024 -
yara-forge Public
Forked from YARAHQ/yara-forgeAutomated YARA Rule Standardization and Quality Assurance Tool
Python GNU General Public License v3.0 UpdatedDec 19, 2023 -
LightningScanner Public
Forked from localcc/LightningScannerA lightning-fast memory pattern scanner, capable of scanning gigabytes of data per second.
C++ MIT License UpdatedNov 9, 2023 -
RmEye Public
Forked from RoomaSec/RmEye戎码之眼是一个window上的基于att&ck模型的威胁监控工具.有效检测常见的未知威胁与已知威胁.防守方的利剑
Python Apache License 2.0 UpdatedOct 25, 2023 -
krabsetw Public
Forked from microsoft/krabsetwKrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.
C++ Other UpdatedSep 25, 2023 -
App-Locker Public
Forked from MateuszJanduraUszu/App-LockerBlocks execution of certain applications.
C++ Apache License 2.0 UpdatedSep 22, 2023 -
WinPmem Public
Forked from Velocidex/WinPmemThe multi-platform memory acquisition tool. ram dump tool
C Apache License 2.0 UpdatedSep 10, 2023 -
ved-ebpf Public
Forked from hardenedvault/ved-ebpfVED-eBPF: Kernel Exploit and Rootkit Detection using eBPF
C++ GNU Affero General Public License v3.0 UpdatedAug 11, 2023 -
pywintrace Public
Forked from fireeye/pywintraceETW Python Library
Python Apache License 2.0 UpdatedAug 11, 2023 -
BLUESPAWN Public
Forked from ION28/BLUESPAWNAn Active Defense and EDR software to empower Blue Teams
C++ GNU General Public License v3.0 UpdatedAug 10, 2023 -
aktaion2 Public
Forked from jzadeh/aktaion2Aktaion is a machine learning open source & active defense (orchestration) prototype. The tool focuses on the detection of exploits based on machine learning techniques, independent of static-based…
Python Apache License 2.0 UpdatedJul 6, 2023 -
fips2zips Public
json used to find all the ZIP codes in a FIPS(Federal Information Processing Standards) code area
Python GNU General Public License v2.0 UpdatedJun 15, 2023 -
Owlyshield Public
Forked from SitinCloud/OwlyshieldOwlyshield is an EDR framework designed to safeguard vulnerable applications from potential exploitation (C&C, exfiltration and impact).
Rust European Union Public License 1.2 UpdatedJun 4, 2023 -
sigar Public
Forked from hyperic/sigarSystem Information Gatherer And Reporter
C Apache License 2.0 UpdatedApr 15, 2023 -
whids Public
Forked from 0xrawsec/whidsOpen Source EDR for Windows
Go GNU Affero General Public License v3.0 UpdatedFeb 25, 2023 -
lkrg Public
Forked from adrelanos/lkrgLinux Kernel Runtime Guard (LKRG). Linux Kernel Runtime Integrity Checking and Exploit Detection. Debian packaging fork only. Fork Homepage: https://www.whonix.org/wiki/Linux_Kernel_Runtime_Guard_L…
C Other UpdatedFeb 23, 2023 -
psexec_noinstall Public
Forked from MzHmO/psexec_noinstallRepository contains psexec, which will help to exploit the forgotten pipe
Python UpdatedFeb 20, 2023 -
LiSa Public
Forked from danielpoliakov/lisaSandbox for automated Linux malware analysis.
Python Apache License 2.0 UpdatedJan 13, 2023 -
ransomware_detection Public
Forked from undo-ransomware/ransomware_detection🔄 Ransomware recovery app for Nextcloud
PHP GNU Affero General Public License v3.0 UpdatedJan 4, 2023 -
Microsoft.Diagnostics.Tracing.Logging Public
Forked from microsoft/Microsoft.Diagnostics.Tracing.Logging.NET library for logging data via EventSource/ETW
C# MIT License UpdatedNov 28, 2022 -
Sealighter Public
Forked from pathtofile/SealighterSysmon-Like research tool for ETW
C++ UpdatedNov 15, 2022 -
ETW2JSON Public
Forked from microsoft/ETW2JSONTool and library to convert ETW logs to JSON files
C# MIT License UpdatedSep 23, 2022 -
flan-vulnerabilityscanner Public
Forked from cloudflare/flanA pretty sweet vulnerability scanner
Python BSD 3-Clause "New" or "Revised" License UpdatedJul 29, 2022 -
hidden-av-filterdrivers Public
Forked from JKornev/hidden🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc
C UpdatedJul 13, 2022 -
EtwStream Public
Forked from neuecc/EtwStreamLogs are event streams. EtwStream provides In-Process and Out-of-Process ObservableEventListener. Everything can compose and output to anywhere by Reactive Extensions.
C# MIT License UpdatedJun 22, 2022 -
-
pypsexec Public
Forked from jborean93/pypsexecRemote Windows execution like PsExec on Python
Python MIT License UpdatedOct 21, 2021 -
dfirt Public
Forked from mamun-sec/dfirtCollect information of Windows PC when doing incident response
PowerShell UpdatedSep 17, 2021