a tool to help operate in EDRs' blind spots
-
Updated
Dec 2, 2024 - Python
a tool to help operate in EDRs' blind spots
戎码之眼是一个window上的基于att&ck模型的威胁监控工具.有效检测常见的未知威胁与已知威胁.防守方的利剑
PowerShell-based Automation of Defender for Endpoint
An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.
Carbon Black API - Python language bindings
Python EDR system Example (server and client-side)
[benchmark] Trajectory similarity computation
Utilizing your Threat data from a MISP instance into CarbonBlack Response by exposing the data in the Threat Intelligence Feed.
Carbon Black - Facebook Threat Exchange Connector
Analysis-oriented command line tool for remote execution and triage via EDRs API
Sample pipeline demo highlighting how to integrate Falcon Container Sensor into ECS Fargate Workloads
Carbon Black - LastLine Binary Detonation Connector
CloudDog is a centralized EDR and WAF, it is able to identify and prevent web application attacks, ssh bruteforce and Suspicious shell commands.
Import Cb Collective Defense Cloud Intelligence Feeds to air-gapped VMware Carbon Black EDR servers
PyCanary: CMD line tool to monitor any directory for file access or file changes, log event, send basic alert to user, and dump and process information collected. There is also a background thread monitoring all created processes and logging them for later analysis.
Add a description, image, and links to the edr topic page so that developers can more easily learn about it.
To associate your repository with the edr topic, visit your repo's landing page and select "manage topics."