Stars
A community-driven repository for threat hunting ideas, methodologies, and research that serves as a central gathering place for hunters to share knowledge, collaborate on techniques, and advance t…
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
Sys Mon! Why yu nuh logging dat?
Random pieces of knowledge — with anecdotes and quotes
A FREE comprehensive reverse engineering tutorial covering x86, x64, 32-bit/64-bit ARM, 8-bit AVR and 32-bit RISC-V architectures.
A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.
Repository documenting how Threat Intelligence and / or a Threat Intelligence Platform can prove its value to an organisation.
Azure Security Resources and Notes
Public Repository of Open Source Tools for Cyber Threat Intelligence Analysts and Researchers
A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.
A repository of advice and guides to share with friends and family who are concerned about their safety during online activities and the security of their devices.
A slightly more fun way to disable windows defender + firewall. (through the WSC api)
This repo is about Active Directory Advanced Threat Hunting
Gram is Klarna's own threat model diagramming tool
This repository provides sample templates for security playbooks against various scenarios when using Amazon Web Services.
Analysis of the Enterprise SAST/DAST product landscape
The Microsoft Defender for Office 365 Recommended Configuration Analyzer (ORCA)
Microsoft Sentinel Incident Tasks Recipes
AutomatedLab is a provisioning solution and framework that lets you deploy complex labs on HyperV and Azure with simple PowerShell scripts. It supports all Windows operating systems from 2008 R2 to…
The GHDB is an index of search queries (we call them dorks) used to find publicly available information, intended for pentesters and security researchers.
CTF challenge (mostly pwn) files, scripts etc
Your template-based BloodHound terminal companion tool
CA Optics - Azure AD Conditional Access Gap Analyzer
matrix (web-based green code rain, made with love)
Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use when investigating a security incident.