MalwareLabMurphy
Human cybersecurity analyst and his trusty Chocolate Labrador. Using this page to follow my favorite GitHub repos and contribute to open source projects.
Raleigh, NC
MalwareLabMurphy's Stars
firstcontributions/first-contributions
🚀✨ Help beginners to contribute to open source projects
certsocietegenerale/IRM
Incident Response Methodologies 2022
splunk/rba
RBA is Splunk's method to aggregate low-fidelity security events as interesting observations tagged with security metadata to create high-fidelity, low-volume alerts.
netbiosX/Checklists
Red Teaming & Pentesting checklists for various engagements
FalconForceTeam/FalconFriday
Hunting queries and detections
swisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
microsoft/SysmonForLinux
Sysmon for Linux
nasbench/SIGMA-Resources
Resources To Learn And Understand SIGMA Rules
reprise99/Sentinel-Queries
Collection of KQL queries
chrivand/twitter_search_threatresponse
Twitter Search to Cisco Threat Response Casebook [v1.0]
chrivand/talos_blog_to_casebook
This is a sample script how to parse the Talos blogs, and automatically add observables to Cisco Casebook.
0xDanielLopez/TweetFeed
TweetFeed collects Indicators of Compromise (IOCs) shared by the infosec community at Twitter. Here you will find malicious URLs, domains, IPs, and SHA256/MD5 hashes.
stuhli/awesome-event-ids
Collection of Event ID ressources useful for Digital Forensics and Incident Response
fastfire/deepdarkCTI
Collection of Cyber Threat Intelligence sources from the deep and dark web
k-bailey/detection-engineering-maturity-matrix
splunk/attack_data
A repository of curated datasets from various attacks
magnologan/awesome-k8s-security
A curated list for Awesome Kubernetes Security resources
olafhartong/sysmon-modular
A repository of sysmon configuration modules
tomnomnom/gron
Make JSON greppable!
trustedsec/SysmonCommunityGuide
TrustedSec Sysinternals Sysmon Community Guide
NextronSystems/APTSimulator
A toolset to make a system look as if it was the victim of an APT attack
murchisd/splunk_pstree_app
Custom Splunk search command to reconstruct a pstree from Sysmon process creation events (EventCode 1)
iamrootsh3ll/AnchorWatch
A Rogue Device Detection Script with Email Alerts Functionality for Windows Subsystem
mitre-attack/mitreattack-python
A python module for working with ATT&CK
mitre-attack/attack-navigator
Web app that provides basic navigation and annotation of ATT&CK matrices
redcanaryco/atomic-red-team
Small and highly portable detection tests based on MITRE's ATT&CK.
rabobank-cdc/DeTTECT
Detect Tactics, Techniques & Combat Threats
microsoft/Microsoft-365-Defender-Hunting-Queries
Sample queries for Advanced hunting in Microsoft 365 Defender
threathunters-io/laurel
Transform Linux Audit logs for SIEM usage
Azure/Azure-Sentinel
Cloud-native SIEM for intelligent security analytics for your entire enterprise.