Pinned Repositories
ail-yara-rules
A set of YARA rules for the AIL framework to detect leak or information disclosure
AlienvaultLabs
Alienvault Labs Projects Random Stuff
awesome-event-ids
Collection of Event ID ressources useful for Digital Forensics and Incident Response
awesome-malware-analysis
A curated list of awesome malware analysis tools and resources
backup-slack
A script for backing up your message history from Slack
canari
Local and Remote Maltego Rapid Transform Development Framework
gdata-client-java
Google gdata client in java
malicious-domain-profiling
Automatically exported from code.google.com/p/malicious-domain-profiling
mwcrawler
Python Malware Crawler for Zoos and Repositories
smart-codegen
smart-codegen project from google code
elhoim's Repositories
elhoim/ail-yara-rules
A set of YARA rules for the AIL framework to detect leak or information disclosure
elhoim/awesome-event-ids
Collection of Event ID ressources useful for Digital Forensics and Incident Response
elhoim/backup-slack
A script for backing up your message history from Slack
elhoim/censys-python
Python Library for Censys
elhoim/crl-monitor
CRL Monitor - X.509 Certificate Revocation List monitoring and X.509/Subject caching
elhoim/DailyIOC
IOC from articles, tweets for archives
elhoim/ExpertRules
This repository contains a set of rules samples that can be directly used with McAfee Endpoint Security, in the Exploit Prevention policy.
elhoim/gopassivedns
PassiveDNS in Go
elhoim/Hello-Goodbye
Available for Chrome, Firefox and Safari and as a blocklist to integrate into existing blockers.
elhoim/InfraFinder
Finds shared attributes across multiple IP addresses by querying Censys
elhoim/LOLBAS
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
elhoim/malware-indicators
Citizen Lab Malware Reports
elhoim/MISP
MISP - Malware Information Sharing Platform & Threat Sharing
elhoim/misp-galaxy
Clusters and elements to attach to MISP events or attributes (like threat actors)
elhoim/MISP-maltego
Set of Maltego transforms to inferface with a MISP instance
elhoim/misp-modules
Modules for expansion services, import and export in MISP
elhoim/misp-taxonomies
Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.
elhoim/misp-warninglists
Warning lists to inform users of MISP about potential false-positives or other information in indicators
elhoim/misp-website
MISP website (jekyll-based)
elhoim/misp2bro
Python script that gets IOC from MISP and converts it into BRO intel files.
elhoim/otterai-api
Unofficial Otter.ai Python API
elhoim/pySigma
Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)
elhoim/pySigma-backend-splunk
pySigma Splunk backend
elhoim/redis-py
Redis Python Client
elhoim/sigma
Generic Signature Format for SIEM Systems
elhoim/signature-base
Signature base for my scanner tools
elhoim/splunk_wineventcode_secanalysis
Windows Event Code Security Analysis app for Splunk.
elhoim/sysmon-modular
A repository of sysmon configuration modules
elhoim/viper
Binary analysis and management framework
elhoim/yarix