dluxtron's Stars
S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet
A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
rootm0s/WinPwnage
UAC bypass, Elevate, Persistence methods
splunk/attack_range
A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk
hlldz/Phant0m
Windows Event Log Killer
tsale/EDR-Telemetry
This project aims to compare and evaluate the telemetry of various EDR products.
splunk/security_content
Splunk Security Content
mdecrevoisier/Microsoft-eventlog-mindmap
Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...
joshhighet/ransomwatch
the transparent ransomware claim tracker 🥷🏼🧅🖥️
circulosmeos/gdown.pl
Google Drive direct download of big files
splunk/attack_data
A repository of curated datasets from various attacks
enigma0x3/Misc-PowerShell-Stuff
random powershell goodness
mvelazc0/BadZure
BadZure orchestrates the setup of Azure AD tenants, populating them with diverse entities while also introducing common security misconfigurations to create vulnerable tenants with multiple attack paths.
netero1010/ScheduleRunner
A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation
mvelazc0/msInvader
M365/Azure adversary simulation tool that generates realistic attack telemetry to help blue teams improve their detection and response capabilities.
mdecrevoisier/Splunk-input-windows-baseline
Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE Att&CK
hire-vladimir/SA-cim_vladiator
Data validator agains Splunk Common Information Model (CIM)
splunk/rba
RBA is Splunk's method to aggregate low-fidelity security events as interesting observations tagged with security metadata to create high-fidelity, low-volume alerts.
jwardsmith/Active-Directory-Exploitation
mvelazc0/SharpShareFinder
SharpShareFinder is a minimalistic network share discovery POC designed to enumerate shares in Windows Active Directory networks leveraging .NET parallelism.
ville87/ADSIx509
PS Scripts for authenticating to LDAP using x509 client certificate
ccl0utier/CorrelationRulesRunner
toadspestcontrol/toadcoin
Get Some!!!