A repository of sysmon configuration modules
-
Updated
Jul 13, 2026 - PowerShell
A repository of sysmon configuration modules
Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic Artifact Events for UEBA, Detect Exploitation events with wide CVE Coverage, and Risk Scoring of CVE, UEBA, Forensic, and MITRE ATT&CK Events.
A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework
Purpleteam scripts simulation & Detection - trigger events for SOC detections
Templates for the Microsoft Threat Modeling Tool
PowerShell-based Windows Server Security Audit Engine by Cyb3rint3l Labs. Measures alignment with the NIS2 directive and maps findings to MITRE ATT&CK tactics & CIS Controls v8 practices. Generates interactive HTML dashboards & structured JSON datasets.
CTRL-ESC-HOST is an assessment methodology for testing for security flaws in Kiosks and Presented Applications.
PowerShell Post-exploitation agent based on Mitre Att&ck framework
Windows environment hunting at scale!
STI ISE 5901 Whitepaper repository
Applied SOC Analysis and Incident Response documentation covering endpoint forensics, network traffic analysis (PCAP), and detection engineering. Demonstrating analyst-level investigative methodology using Splunk, Wireshark, and Sysinternals.
Presentations
CafeSec Lab - defensive research and tooling for internet cafe, gaming venue, and shared-PC security
GitHub Action for local execution of Atomic Red Team tests using Invoke-Atomic
Small and highly portable detection tests based on MITRE's ATT&CK.
Исследование тактики Initial Access (TA0001) из матрицы MITRE ATT&CK для Kubernetes
Windows security auditing, event generation, and MITRE ATT&CK mapping toolkit for detection validation.
Splunk-based home SOC lab for Windows and Linux log analysis, detection engineering, and security investigation workflows.
Add a description, image, and links to the mitre-attack topic page so that developers can more easily learn about it.
To associate your repository with the mitre-attack topic, visit your repo's landing page and select "manage topics."