Debugging
Debugging utilities
detecting t1003 credential dumping with edr
GitHubDetect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials
detecting t1548 abuse elevation control mechanism
GitHubDetect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation
extracting browser history artifacts
GitHubExtract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge
extracting credentials from memory dump
GitHubExtract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using
hardening docker daemon configuration
GitHubHarden the Docker daemon by configuring daemon.json with user namespace remapping, TLS authentication, rootless
hunting for beaconing with frequency analysis
GitHubIdentify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis,
hunting for cobalt strike beacons
GitHubDetect Cobalt Strike beacon network activity using default TLS certificate signatures (serial 8BB00EE), JA3/JA3S/JARM
hunting for command and control beaconing
GitHubDetect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation
hunting for data exfiltration indicators
GitHubHunt for data exfiltration through network traffic analysis, detecting unusual data flows, DNS tunneling, cloud
hunting for data staging before exfiltration
GitHubDetect data staging activity before exfiltration by monitoring for archive creation with 7-Zip/RAR, unusual temp
hunting for dns based persistence
GitHubHunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse,
hunting for dns tunneling with zeek
GitHubDetect DNS tunneling and data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive
hunting for domain fronting c2 traffic
GitHubDetect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate
hunting for lateral movement via wmi
GitHubDetect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for
hunting for living off the land binaries
GitHubProactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while
hunting for ntlm relay attacks
GitHubDetect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying
hunting for persistence mechanisms in windows
GitHubSystematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services,
hunting for persistence via wmi subscriptions
GitHubHunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI
hunting for process injection techniques
GitHubDetect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection
hunting for registry run key persistence
GitHubDetect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry
hunting for startup folder persistence
GitHubDetect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation,
hunting for suspicious scheduled tasks
GitHubHunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious
hunting for t1098 account manipulation
GitHubHunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group
hunting for unusual service installations
GitHubDetect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event