Skip to content
View umrc's full-sized avatar

Block or report umrc

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

Threat hunting

27 repositories

Splunk code (SPL) for serious threat hunters and detection engineers.

268 41 Updated Jan 15, 2024

An analytical framework for network traffic and behavioral analytics

Python 449 86 Updated Dec 7, 2022

Main Sigma Rule Repository

Python 8,590 2,245 Updated Jan 13, 2025

The idea is simply to save some quick notes that will make it easier for Splunk users to leverage KQL (Kusto), especially giving projects requiring both technologies (Splunk and Azure/Sentinel) or …

39 6 Updated Nov 7, 2020

Some Threat Hunting queries useful for blue teamers

123 23 Updated May 13, 2022

Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE Att&CK

90 12 Updated Oct 7, 2024

UAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD…

Shell 837 127 Updated Jan 14, 2025

Comprehensive toolkit for Ghidra headless.

Python 353 21 Updated Aug 4, 2023

✨ A curated list of awesome threat detection and hunting resources 🕵️‍♂️

3,959 669 Updated Jul 15, 2024

A powerful and user-friendly browser extension that streamlines investigations for security professionals.

JavaScript 342 43 Updated Aug 21, 2024

Simple (relatively) things allowing you to dig a bit deeper than usual.

C 3,271 535 Updated Jan 1, 2025

Best Practice Auditd Configuration

1,540 271 Updated Oct 16, 2024

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to run a full investigation against a customer’s Azur…

Python 917 80 Updated Nov 18, 2024

Detect Tactics, Techniques & Combat Threats

SCSS 2,091 338 Updated Jan 9, 2025

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

PowerShell 310 34 Updated Oct 21, 2024

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on a VM.

PowerShell 6,775 936 Updated Jan 13, 2025

Collection of KQL queries

1,455 346 Updated Dec 22, 2024

The TTPForge is a Cybersecurity Framework for developing, automating, and executing attacker Tactics, Techniques, and Procedures (TTPs).

Go 353 35 Updated Dec 5, 2024

Encyclopedia for Executables

PowerShell 424 46 Updated Nov 9, 2021

This is a collection of threat detection rules / rules engines that I have come across.

277 20 Updated May 5, 2024

AADInternals PowerShell module for administering Azure AD and Office 365

PowerShell 1,342 219 Updated Dec 13, 2024

KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.

Python 1,323 240 Updated Jan 12, 2025

Different methods to get current username without using whoami

C# 173 17 Updated Feb 12, 2024

A query aggregator for OSINT based threat hunting

Ruby 870 101 Updated Jan 8, 2025

Interactive Azure Sentinel Notebooks provides security insights and actions to investigate anomalies and hunt for malicious behaviors.

Jupyter Notebook 571 194 Updated Jan 8, 2025

Digging Deeper....

Go 3,049 501 Updated Jan 14, 2025

Secrets Patterns DB: The largest open-source Database for detecting secrets, API keys, passwords, tokens, and more.

Python 1,070 134 Updated Jan 26, 2024