Skill Market

Debugging

Debugging utilities

detecting t1003 credential dumping with edr

GitHub

Detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting t1548 abuse elevation control mechanism

GitHub

Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

extracting browser history artifacts

GitHub

Extract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

extracting credentials from memory dump

GitHub

Extract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hardening docker daemon configuration

GitHub

Harden the Docker daemon by configuring daemon.json with user namespace remapping, TLS authentication, rootless

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hunting for beaconing with frequency analysis

GitHub

Identify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis,

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hunting for cobalt strike beacons

GitHub

Detect Cobalt Strike beacon network activity using default TLS certificate signatures (serial 8BB00EE), JA3/JA3S/JARM

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hunting for command and control beaconing

GitHub

Detect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hunting for data exfiltration indicators

GitHub

Hunt for data exfiltration through network traffic analysis, detecting unusual data flows, DNS tunneling, cloud

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hunting for data staging before exfiltration

GitHub

Detect data staging activity before exfiltration by monitoring for archive creation with 7-Zip/RAR, unusual temp

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hunting for dns based persistence

GitHub

Hunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse,

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hunting for dns tunneling with zeek

GitHub

Detect DNS tunneling and data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hunting for domain fronting c2 traffic

GitHub

Detect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hunting for lateral movement via wmi

GitHub

Detect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hunting for living off the land binaries

GitHub

Proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hunting for ntlm relay attacks

GitHub

Detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hunting for persistence mechanisms in windows

GitHub

Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services,

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hunting for persistence via wmi subscriptions

GitHub

Hunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hunting for process injection techniques

GitHub

Detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hunting for registry run key persistence

GitHub

Detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hunting for startup folder persistence

GitHub

Detect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation,

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hunting for suspicious scheduled tasks

GitHub

Hunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hunting for t1098 account manipulation

GitHub

Hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

hunting for unusual service installations

GitHub

Detect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents