Pinned Repositories
awesome-threat-intelligence
A curated list of Awesome Threat Intelligence resources
ebpf-docker-lsm
Monitor and block specified processes and network connections with this docker-aware KRSI (BPF+LSM) security tool
falco-attack-navigator
linux-siem-audit-configs
Auditd, OSquery, and Falco low-volume process and filesystem auditing configs built for SIEM ingestion
memfd-process-hide
Hide process execution from auditd or dynamically load remote binaries using memfd+fexecve syscalls
splunk-ta-abusech
Collection of modular inputs to fetch data from AbuseCH MalwareBazaar, URLhaus, and ThreatFox
thm-writeup-apiwizardsbreach
Writeup for APIWizards Breach room in TryHackMe
windows-siem-checklist
petFind
Lits project, PetFinder
maxvarm's Repositories
maxvarm/linux-siem-audit-configs
Auditd, OSquery, and Falco low-volume process and filesystem auditing configs built for SIEM ingestion
maxvarm/thm-writeup-apiwizardsbreach
Writeup for APIWizards Breach room in TryHackMe
maxvarm/ebpf-docker-lsm
Monitor and block specified processes and network connections with this docker-aware KRSI (BPF+LSM) security tool
maxvarm/splunk-ta-abusech
Collection of modular inputs to fetch data from AbuseCH MalwareBazaar, URLhaus, and ThreatFox
maxvarm/windows-siem-checklist
maxvarm/falco-attack-navigator
maxvarm/memfd-process-hide
Hide process execution from auditd or dynamically load remote binaries using memfd+fexecve syscalls