#DFIR #Python #YARA #Golang #SIEM #SOC #Sigma #Malware
Highlights
- 1 discussion answered
Block or Report
Block or report Neo23x0
Report abuse
Contact GitHub support about this user’s behavior. Learn more about reporting abuse.
Report abusePinned
-
-
NextronSystems/APTSimulator Public
A toolset to make a system look as if it was the victim of an APT attack
2,648 contributions in the last year
Less
More
Contribution activity
March 2022
Created 78 commits in 7 repositories
Created a pull request in SigmaHQ/sigma that received 2 comments
Opened 11 other pull requests in 2 repositories
SigmaHQ/sigma
1
open
9
merged
- LSASS access rule split up
- refactor: lsass dump files names, new: NTDS.dit exfiltration activity
- docs: changed UltraVNC flags rule < Gamaredon
- fix: unused filter
- fix: adjusted rules that use utf16le, extended others
- Imphash rule adjustments
- fix: missing escaped backslashes, rule: ntdll redirect
- Multiple adjustments in different rules
- refactor: PowerShell Defender modifications
- Minor changes, new PS downloader strings
telekom-security/malware_analysis
1
open
Reviewed 1 pull request in 1 repository
SigmaHQ/sigma
1 pull request
Created an issue in SigmaHQ/sigma that received 1 comment
Splunk Backend Prefix
@frack113 : I think you've added this line recently. Shouldn't this have a WinEventLog: prefix like the others?
sigma/tools/config/splunk-window…
1
comment


