Hi! Thanks For Stopping By 😊 <!-- nasbench/nasbench is a ✨ _special_ ✨ repository because its README.md (this file) appears on your GitHub profile. Here are some ideas to get…
Hi! Thanks For Stopping By 😊
<!--
nasbench/nasbench is a ✨ _special_ ✨ repository because its README.md (this file) appears on your GitHub profile.
Here are some ideas to get you started:
- 🔭 I’m currently working on ...
- 🌱 I’m currently learning ...
- 👯 I’m looking to collaborate on anything related to Detection Engineering, DIFR and
- 🤔 I’m looking for help with ...
- 💬 Ask me about ...
- 📫 How to reach me: ...
- 😄 Pronouns: ...
- ⚡ Fun fact: ...
Notable Contributions / Creations
- SIGMA - Generic Signature Format for SIEM Systems (core maintainer)
- SIGMA HQ Rule Management GUI (author)
- Malicious Command-Line (MAL-CL) (author)
- EVTX-ETW-Resources (co-author and maintainer)
- LOLDrivers (co-creator and maintainer)
- LOLRMM (co-creator and maintainer)
- Symantec-EDR-Internals
- Sigconverter (maintainer)
- Misc-Research
- Information Security Mind Maps
- C2 Matrix (contributor)
Infosec Research Blog
I write a blog on medium about Detection, DFIR, Windows Internals, Malware and much more. Check it out here!
Attributed CVEs
| CVE | Description |
|-----|-------------|
| CVE-2019-19547 | Unauthenticated XSS in the Symantec EDR (SEDR) |
| CVE-2020-5839 | Information Disclosure In Symantec EDR (SEDR) |
| CVE-2020-12593 | Information Disclosure In Symantec EDR (SEDR) |
| CVE-2021-44750 | Arbitrary Code Execution in the WithSecure Support Tool |
| CVE-2022-1823 | Improper privilege management vulnerability in McAfee Consumer Product Removal Tool |
| CVE-2022-1824 | An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool |
| CVE-2022-37025 | Improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) |
-
EVTX-ETW-Resources
Event Tracing For Windows (ETW) Resources
Python ★ 431 7mo agoExplain → -
MindMaps
#ThreatHunting #DFIR #Malware #Detection Mind Maps
★ 307 4y agoExplain → -
SIGMA-Resources
Resources To Learn And Understand SIGMA Rules
★ 185 3y agoExplain → -
Eventlog_Compendium
The Eventlog Compendium is the go-to resource for understanding Windows Event Logs.
Python ★ 54 1y agoExplain → -
SEDR-Internals
Symantec EDR Internals
★ 31 4y agoExplain → -
procmon-malware-analysis-filters
Repository containing malware analysis filters for the Windows SysInternals' - Process Monitor tool
★ 21 5y agoExplain → -
Multi-Threaded-BruteForcer
A script that automates a brute-force attack on a login page
Python ★ 13 8y agoExplain → -
Awesome-Detection-Engineering
Resources and Discussions About Detection Engineering
★ 12 3y agoExplain → -
sigma ⑂
Generic Signature Format for SIEM Systems
Python ★ 10 6d agoExplain → -
sedr-localdatastore-parser
Parser for Symantec EDR "localdatastore" folder
Python ★ 8 4y agoExplain → -
Encoder-Decoder
A python script that contains multiple functionalities (Hashing, Encoding/Decoding...etc.)
Python ★ 6 8y agoExplain → -
DefenderYara ⑂
Extracted Yara rules from Windows Defender mpavbase and mpasbase
★ 4 2y agoExplain → -
LOLDrivers ⑂
Living Off The Land Drivers
YARA ★ 4 1y agoExplain → -
Slides
A collection of my slides and presentations
★ 4 4y agoExplain → -
BigBountyRecon ⑂
BigBountyRecon tool utilises 58 different techniques using various Google dorks and open source tools to expedite the process of initial reconnaissance on the target organisation.
★ 3 5y agoExplain → -
droid ⑂
A pySigma wrapper to manage detection rules.
★ 3 1y agoExplain → -
atomic-red-team ⑂
Small and highly portable detection tests based on MITRE's ATT&CK.
C ★ 3 1mo agoExplain → -
LawEnforcementResources ⑂
Resources provided by the community that can serve to be useful for Law Enforcement worldwide
★ 3 3y agoExplain → -
Ransomware-Tool-Matrix ⑂
A resource containing all the tools each ransomware gangs uses
★ 3 1y agoExplain → -
HijackLibs ⑂
Project for tracking publicly disclosed DLL Hijacking opportunities.
★ 2 1y agoExplain → -
MAL-CL ⑂
MAL-CL (Malicious Command-Line)
★ 2 1y agoExplain → -
detection-rules ⑂
No description.
★ 2 1y agoExplain → -
Creds ⑂
Some usefull Scripts and Executables for Pentest & Forensics
★ 2 4y agoExplain → -
sysmon-config ⑂
Sysmon configuration file template with default high-quality event tracing
★ 2 1y agoExplain → -
LOLRMM ⑂
LotL RMM
MDX ★ 2 11mo agoExplain → -
SysmonCommunityGuide ⑂
TrustedSec Sysinternals Sysmon Community Guide
★ 2 2y agoExplain → -
The_Shelf ⑂
Retired TrustedSec Capabilities
★ 2 2y agoExplain → -
winevt-kb ⑂
Windows Event Log Knowledge Base
★ 2 1y agoExplain → -
Zircolite ⑂
A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
★ 2 1y agoExplain → -
wil ⑂
Windows Implementation Library
C++ ★ 2 2y agoExplain → -
threathunters ⑂
No description.
YARA ★ 2 2y agoExplain → -
awesome-event-ids ⑂
Collection of Event ID ressources useful for Digital Forensics and Incident Response
★ 2 4y agoExplain → -
DFIRPowerShellScripts ⑂
Various PowerShells scripts I've made to automate some of the boring stuff in my everyday DFIR journey!
PowerShell ★ 2 3y agoExplain → -
detection.studio ⑂
Convert Sigma rules to SIEM queries, directly in your browser.
★ 1 6d agoExplain → -
pySigma ⑂
Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)
Python ★ 1 1y agoExplain → -
sandbox-attacksurface-analysis-tools ⑂
Set of tools to analyze Windows sandboxes for exposed attack surface.
★ 1 1y agoExplain → -
vscode-sigma ⑂
No description.
TypeScript ★ 1 8mo agoExplain → -
nasbench
No description.
★ 1 5mo agoExplain → -
GhostLoader ⑂
GhostLoader - AppDomainManager - Injection - 攻壳机动队
★ 1 6y agoExplain → -
PersistenceSniper ⑂
Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Made with ❤️ by @last0x00
★ 1 3y agoExplain → -
panopticon ⑂
A YARA Rule Performance Measurement Tool
YARA ★ 1 3y agoExplain → -
NimPlant ⑂
A light-weight first-stage C2 implant written in Nim.
★ 1 3y agoExplain → -
signature-base ⑂
Signature base for my scanner tools
YARA ★ 1 2y agoExplain → -
pySigma-backend-elasticsearch ⑂
pySigma Elasticsearch backend
Python ★ 1 2y agoExplain → -
SIGMA-detection-rules ⑂
Set of SIGMA rules (>320) mapped to MITRE ATT&CK tactic and techniques
★ 1 2y agoExplain → -
pySigma-validators-sigmaHQ ⑂
No description.
Python ★ 1 1y agoExplain → -
LOLBAS ⑂
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
XSLT ★ 1 1y agoExplain → -
attack_range ⑂
A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk
★ 1 1y agoExplain → -
popkorn-artifact ⑂
No description.
★ 1 3y agoExplain → -
sigmahq.github.io ⑂
Official Website Of The Sigma Project
Vue ★ 1 1y agoExplain → -
threat-intel ⑂
This repository contains supplemental items including IOCs, and signatures discussed in Huntress blogposts, and other media.
YARA ★ 1 1y agoExplain → -
SXSEXP ⑂
Expand compressed files from WinSxS folder
★ 1 2y agoExplain → -
EDR-Telemetry ⑂
This project aims to compare and evaluate the telemetry of various EDR products.
PowerShell ★ 1 3y agoExplain → -
VanillaWindowsReference ⑂
A repo that contains recursive dir listings of a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update.
★ 1 3y agoExplain → -
pywintrace ⑂
ETW Python Library
★ 1 6y agoExplain → -
SEPparser ⑂
Script for parsing Symantec Endpoint Protection logs, VBNs, and ccSubSDK database.
Python ★ 1 2y agoExplain → -
Yara-Rules
No description.
YARA ★ 1 4y agoExplain → -
CVE-2020-12593
CVE-2020-12593 POC
★ 1 5y agoExplain → -
CVE-2020-5839
CVE-2020-5839 POC
★ 1 5y agoExplain → -
ManageEngine-Application-Manager-XSS-POC
ZOHO Manage Engine Application Manager - XSS POC
★ 1 5y agoExplain → -
CVE-2019-19547
CVE-2019-19547 POC
★ 1 5y agoExplain → -
winprocs.dfir.tips ⑂
No description.
★ 1 5y agoExplain → -
CTFs
CTF's Writeups
Python ★ 1 7y agoExplain → -
security_content ⑂
Splunk Security Content
Python ★ 0 9d agoExplain → -
Simpleator ⑂
Simpleator ("Simple-ator") is an innovative Windows-centric x64 user-mode application emulator that leverages several new features that were added in Windows 10 Spring Update (1803), also called "Redstone 4", with additional improvements that were made in Windows 10 October Update (1809), aka "Redstone 5".
★ 0 7y agoExplain → -
Crassus ⑂
No description.
★ 0 7mo agoExplain → -
ta-ollama ⑂
Splunk Technology Add-on for monitoring Ollama LLM deployments. Features file monitoring of server logs, HEC integration for custom telemetry, and CIM compliance for enterprise security. Provides HTTP access log parsing, prompt analytics, and built-in data redaction. Compatible with Splunk Cloud Platform
★ 0 7mo agoExplain → -
sigconverter.io ⑂
A opensource sigma convertion tool built using pysigma
JavaScript ★ 0 1y agoExplain → -
FindETWProviderImage ⑂
Quickly search for references to a GUID in DLLs, EXEs, and drivers
★ 0 4y agoExplain → -
sigma-specification ⑂
Sigma rule specification
★ 0 1y agoExplain → -
sensor-mappings-to-attack ⑂
Sensor Mappings to ATT&CK is a collection of resources to assist cyber defenders with understanding which sensors and events can help detect real-world adversary behaviors in their environments.
Python ★ 0 1y agoExplain → -
ThreatHunting-Keywords-sigma-rules ⑂
Sigma detection rules for hunting with the threathunting-keywords project
Python ★ 0 1y agoExplain → -
Sigma-Rules ⑂
Rules generated from our investigations.
Shell ★ 0 1y agoExplain → -
sigma-cli ⑂
The Sigma command line interface based on pySigma
Python ★ 0 1y agoExplain → -
bootloaders ⑂
No description.
YARA ★ 0 1y agoExplain → -
terminal ⑂
The new Windows Terminal and the original Windows console host, all in the same place!
★ 0 2y agoExplain → -
nt5src ⑂
Source code of Windows XP (NT5). Leaks are not from me. I just extracted the archive and cabinet files.
★ 0 3y agoExplain → -
conference_talks ⑂
Slides from various conference talks
★ 0 3y agoExplain → -
python-sdb ⑂
Pure Python parser for Application Compatibility Shim Databases (.sdb files)
★ 0 5y agoExplain → -
schemastore ⑂
A collection of JSON schema files including full API
JavaScript ★ 0 2y agoExplain → -
windows-itpro-docs ⑂
This repository is used for Windows client for IT Pro content on Microsoft Learn.
★ 0 2y agoExplain → -
pySigma-backend-QRadar-AQL ⑂
QRadar AQL backend for converting Sigma rules to QRadar AQL queries
★ 0 2y agoExplain → -
SigmAIQ ⑂
No description.
★ 0 2y agoExplain → -
WSL ⑂
Issues found on WSL
★ 0 2y agoExplain → -
InsightEngineering ⑂
Hardcore Debugging
★ 0 2y agoExplain → -
license-list-XML ⑂
This is the repository for the master files that comprise the SPDX License List
Makefile ★ 0 2y agoExplain → -
PoCSubjectInterfacePackage ⑂
A proof-of-concept subject interface package (SIP) used to demonstrate digital signature subversion attacks.
★ 0 8y agoExplain → -
pySigma-backend-insightidr ⑂
No description.
★ 0 2y agoExplain → -
pySigma-backend-splunk ⑂
pySigma Splunk backend
★ 0 2y agoExplain → -
cookiecutter-pySigma-backend ⑂
pySigma Cookiecutter backend template
★ 0 2y agoExplain → -
VISION-ProcMon ⑂
A ProcessMonitor visualization application written in rust.
★ 0 2y agoExplain → -
artifacts ⑂
Digital Forensics Artifact Repository
★ 0 3y agoExplain → -
ProcMonXv2 ⑂
Process Monitor X v2
★ 0 3y agoExplain → -
munin ⑂
Online hash checker for Virustotal and other services
★ 0 3y agoExplain → -
persistence-info.github.io ⑂
No description.
★ 0 3y agoExplain → -
LocalPotato ⑂
POC CVE-2023-21746
★ 0 3y agoExplain → -
aurora-agent-manual ⑂
Aurora Agent User Manual
Python ★ 0 3y agoExplain → -
evtx-baseline ⑂
A repository hosting example goodware evtx logs containing sample software installation and basic user interaction
★ 0 3y agoExplain → -
component-object-model-sample ⑂
Sample code for Component Object Model (COM) setup and registration.
★ 0 4y agoExplain → -
w32 ⑂
A wrapper of windows apis for the Go Programming Language.
★ 0 5y agoExplain → -
OSSEM-DD ⑂
OSSEM Data Dictionaries
Python ★ 0 3y agoExplain → -
Http-Asynchronous-Reverse-Shell ⑂
[POC] Asynchronous reverse shell using the HTTP protocol.
C# ★ 0 4y agoExplain → -
BabyShark ⑂
Basic C2 Server
HTML ★ 0 4y agoExplain → -
trevorc2 ⑂
TrevorC2 is a legitimate website (browsable) that tunnels client/server communications for covert command execution.
C ★ 0 5y agoExplain →
No repos match these filters.