Skip to content

Assorted, MIT licensed, threat hunting rules from @bradleyjkemp

License

Notifications You must be signed in to change notification settings

bradleyjkemp/threathunting

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

7 Commits
 
 
 
 
 
 
 
 

Repository files navigation

Assorted, MIT licensed, threat hunting rules from @bradleyjkemp

Contents

  • apfell/: Sigma rules for detecting the https://github.com/its-a-feature/Mythic MacOS implant:
    • Temporary keychain file created on Apfell agent launch as part of its session key generation implementation
    • IOCs for a couple of the agent functions built-in to the standard Apfell payload

About

Assorted, MIT licensed, threat hunting rules from @bradleyjkemp

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Sponsor this project

 

Packages

No packages published