Please no pull requests for this repository. Thanks!
created at May 8, 2015, 11:21 a.m.
Adversary tradecraft detection, protection, and hunting
created at March 25, 2016, 11:28 a.m.
Windows Events Attack Samples
created at March 15, 2019, 8:45 a.m.
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
created at Sept. 18, 2020, 5:04 a.m.
A toolset to make a system look as if it was the victim of an APT attack
created at Feb. 3, 2018, 2:19 p.m.
A repository of sysmon configuration modules
created at Jan. 13, 2018, 9:20 p.m.
Investigate malicious Windows logon by visualizing and analyzing Windows event log
created at Nov. 24, 2017, 6:07 a.m.
StreamAlert is a serverless, realtime data analysis framework which empowers you to ingest, analyze, and alert on data from any environment, using datasources and alerting logic you define.
created at Jan. 22, 2017, 1:10 a.m.
Rapidly Search and Hunt through Windows Forensic Artefacts
created at Aug. 13, 2021, 1:07 p.m.
Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management
created at March 24, 2015, 8:15 p.m.
OS X Auditor is a free Mac OS X computer forensics tool
created at June 19, 2013, 5:26 p.m.