Skip to content

MatthewDemaske/ThreatHuntingStuff

Repository files navigation

ThreatHuntingStuff

Lots of stuff coming soon. Need to start dumping my favorite Splunk queries. Company is currently switching webhosts, so past blog material is unavailable atm. I did upload a local HTML copy of the netshell helper DLL persistence/loading technique due to it making Mitre's ATT&CK matrix this month. The link on the MITRE wiki is broken.

https://attack.mitre.org/wiki/Technique/T1128

Link to HTML view

https://htmlpreview.github.io/?https://github.com/MatthewDemaske/blogbackup/blob/master/netshell.html

4/8/17 Sigma repo created

Reference: https://github.com/Neo23x0/sigma

About

Useful Threat Hunting Stuff

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published