Highlights
BluePurpleTeam
Pre-Built Vulnerable Environments Based on Docker-Compose
快速搭建各种漏洞环境(Various vulnerability environment)
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).
Materials for Windows Malware Analysis training (volume 1)
A library to load, manipulate, dump PE files. See also: https://github.com/hasherezade/libpeconv_tpl
A Fast (and safe) parser for the Windows XML Event Log (EVTX) format
A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups
StreamAlert is a serverless, realtime data analysis framework which empowers you to ingest, analyze, and alert on data from any environment, using datasources and alerting logic you define.
A curated list of tools for incident response
Monzo's real-time incident response and reporting tool ⚡️
Tracking history of USB events on GNU/Linux
Trust & Safety tools for working together to fight digital harms.
cve-search - a tool to perform local searches for known vulnerabilities
AIL framework - Analysis Information Leak framework
AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project
Small and highly portable detection tests based on MITRE's ATT&CK.
Invoke-AtomicRedTeam is a PowerShell module to execute tests as defined in the [atomics folder](https://github.com/redcanaryco/atomic-red-team/tree/master/atomics) of Red Canary's Atomic Red Team p…
Public Repo for Atomic Test Harness
Chain Reactor is an open source framework for composing executables that simulate adversary behaviors and techniques on Linux endpoints.
An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.
ipsets dynamically updated with firehol's update-ipsets.sh script
Scan files or process memory for CobaltStrike beacons and parse their configuration
Public Repository of Open Source Tools for Cyber Threat Intelligence Analysts and Researchers