nasbench
Detection Engineering | Threat Hunting | Malware Analysis | Windows Internals | DFIR
@Splunk @SigmaHQ @magicsword-ioHAL
Pinned Repositories
MAL-CL
MAL-CL (Malicious Command-Line)
sigconverter.io
An opensource sigma conversion tool built using pysigma
C2-Matrix-Indicators
This repository aims to collect and document indicators from the different C2's listed in the C2-Matrix
EVTX-ETW-Resources
Event Tracing For Windows (ETW) Resources
MindMaps
#ThreatHunting #DFIR #Malware #Detection Mind Maps
Misc-Research
A collection of tools, scripts and personal research
SEDR-Internals
Symantec EDR Internals
SIGMA-Resources
Resources To Learn And Understand SIGMA Rules
sigma
Main Sigma Rule Repository
nasbench's Repositories
nasbench/EVTX-ETW-Resources
Event Tracing For Windows (ETW) Resources
nasbench/Misc-Research
A collection of tools, scripts and personal research
nasbench/sigma
Generic Signature Format for SIEM Systems
nasbench/LOLDrivers
Living Off The Land Drivers
nasbench/Ransomware-Tool-Matrix
A resource containing all the tools each ransomware gangs uses
nasbench/sysmon-config
Sysmon configuration file template with default high-quality event tracing
nasbench/Zircolite
A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
nasbench/atomic-red-team
Small and highly portable detection tests based on MITRE's ATT&CK.
nasbench/droid
A pySigma wrapper to manage detection rules.
nasbench/LOLRMM
LotL RMM
nasbench/sigmahq.github.io
Official Website Of The Sigma Project
nasbench/SysmonCommunityGuide
TrustedSec Sysinternals Sysmon Community Guide
nasbench/The_Shelf
Retired TrustedSec Capabilities
nasbench/threat-intel
This repository contains supplemental items including IOCs, and signatures discussed in Huntress blogposts, and other media.
nasbench/attack_range
A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk
nasbench/bootloaders
nasbench/HijackLibs
Project for tracking publicly disclosed DLL Hijacking opportunities.
nasbench/LOLBAS
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
nasbench/pySigma
Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)
nasbench/pySigma-backend-elasticsearch
pySigma Elasticsearch backend
nasbench/pySigma-validators-sigmaHQ
nasbench/sensor-mappings-to-attack
Sensor Mappings to ATT&CK is a collection of resources to assist cyber defenders with understanding which sensors and events can help detect real-world adversary behaviors in their environments.
nasbench/sigconverter.io
A opensource sigma convertion tool built using pysigma
nasbench/sigma-cli
The Sigma command line interface based on pySigma
nasbench/SIGMA-detection-rules
Set of SIGMA rules (>320) mapped to MITRE ATT&CK tactic and techniques
nasbench/Sigma-Rules
Rules generated from our investigations.
nasbench/sigma-specification
Sigma rule specification
nasbench/signature-base
Signature base for my scanner tools
nasbench/ThreatHunting-Keywords-sigma-rules
Sigma detection rules for hunting with the threathunting-keywords project
nasbench/vscode-sigma