Make some noise - a note on detections
Most detection engineers already know this, but based on experience many companies will fail to consider noise in their detection strategy.
Most detection engineers already know this, but based on experience many companies will fail to consider noise in their detection strategy.
Can we silence Defender for Endpoint using a rogue VPN-server?
A little weekend project to help build filters for MISP and misp2sentinel
Yes. Sort of, at least. Join me to explore how we can potentially use WoW and it's ecosystem as a C2
Simple tool to detect Azure Lighthouse delegations and automate persistence setup.
Module for interacting with a MISP server using PowerShell.
PowerShell module for sending indicators of compromise to the Upload Indicators API (Microsoft Sentinel).
Proof of concept PowerShell functions for sending TI from MISP to SentinelOne.
Repository for publishing scripts related to Microsoft Sentinel.
Collection of ARM and other templates for Microsoft Sentinel.
vibe coded nonsense that allows you to unlike instagram posts in firefox.
An attempt at creating mermaid diagrams for markdown as code.
Proof of concept PowerShell-functions for sending TI from MISP to SentinelOne.