Skip to content
View mthcht's full-sized avatar
🏠
Working from home
🏠
Working from home

Sponsors

@kick707

Highlights

  • Pro

Organizations

@s1community @lolc2 @BADGUIDS @sinkholed

Block or report mthcht

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Sublime rules for email attack detection, prevention, and threat hunting.

YAML 306 63 Updated May 5, 2025

Public static website for the D3FEND project. For the D3FEND ontology repo see: https://github.com/d3fend/d3fend-ontology

HTML 81 15 Updated Apr 21, 2025

Stakeholder-Specific Vulnerability Categorization

Python 147 36 Updated May 5, 2025

A knowledge base of actionable Incident Response techniques

Python 636 117 Updated May 31, 2022

TheHive: a Scalable, Open Source and Free Security Incident Response Platform

Scala 3,650 649 Updated Dec 5, 2022

MCP Server for Ghidra

Java 4,588 318 Updated Apr 22, 2025

Matkap - hunt down malicious Telegram bots

Python 559 93 Updated Apr 3, 2025

Resolving sinkholed domains

HTML 4 Updated Mar 7, 2025

Threat-hunting tool for Linux

Rust 830 64 Updated May 5, 2025

Small and highly portable detection tests based on MITRE's ATT&CK.

C 10,515 2,904 Updated May 5, 2025
C++ 29 2 Updated Feb 28, 2025

Splunk Content Control Tool

Python 112 27 Updated May 2, 2025

Block file creation with use of eBPF

C 4 2 Updated Feb 21, 2025

FJTA (Forensic Journal Timeline Analyzer) is a tool that analyzes Linux filesystem (EXT4, XFS) journals (not systemd-journald), generates timelines, and detects suspicious activities.

Python 63 6 Updated Apr 4, 2025

Windows kernel and user mode emulation.

Python 1,640 245 Updated Apr 1, 2025

A tool for checking if MFA is enabled on multiple Microsoft Services

PowerShell 1,493 204 Updated Mar 4, 2025

This repository is for Indicators of Compromise (IOCs) from Zscaler ThreatLabz public reports

YARA 73 11 Updated Nov 19, 2024

A Python reference implementation for CZDS download zone file API

Python 110 42 Updated Apr 2, 2025
Python 686 93 Updated Mar 4, 2025

BadZure orchestrates the setup of Azure AD tenants, populating them with diverse entities while also introducing common security misconfigurations to create vulnerable tenants with multiple attack …

Python 453 27 Updated Apr 10, 2025

🕵️‍♂️ All-in-one OSINT tool for analysing any website

TypeScript 24,921 1,941 Updated Apr 27, 2025

Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques

357 74 Updated Jan 15, 2025

Records an executable's network activity into a Full Packet Capture file (.pcap) and much more.

C# 378 20 Updated Apr 6, 2025

A comprehensive list of usable Entra ID first-party clients with pre-consented Microsoft Graph scopes, in a simple YAML-file explorable with a simple HTML GUI.

HTML 103 6 Updated Mar 26, 2025

攻击流量包,辅助安全运营/分析人员,HVV蓝队工程师开展流量攻击研判工作

62 8 Updated Sep 7, 2023

Because AV evasion should be easy.

Go 713 72 Updated Nov 28, 2024

Analyse your malware to surgically obfuscate it

Python 465 55 Updated Feb 26, 2025

View ETW Provider manifest

C# 482 73 Updated Nov 1, 2024

Events from all manifest-based and mof-based ETW providers across Windows 10 versions

C# 295 60 Updated May 2, 2024
Next