Pinned Repositories
EDRSilencer
A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.
sigma
Generic Signature Format for SIEM Systems
WindowsAdvancedAuditPolicyMap
The main purpose of this project is to establish an exhaustive map of the correspondence between Windows advanced audit policy settings and event ids.
EDRSilencer
A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.
sigma
Main Sigma Rule Repository
little-kawa's Repositories
little-kawa/WindowsAdvancedAuditPolicyMap
The main purpose of this project is to establish an exhaustive map of the correspondence between Windows advanced audit policy settings and event ids.
little-kawa/EDRSilencer
A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.
little-kawa/sigma
Generic Signature Format for SIEM Systems