edr topic
cbapi-python
Carbon Black API - Python language bindings
Elkeid
Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It is derived from ByteDance's internal best practices...
iMonitor
iMonitor(冰镜 - 终端行为分析系统)
TiEtwAgent
PoC memory injection detection agent based on ETW, for offensive and defensive research purposes
MineSweeper
Windows user-land hooks manipulation tool.
redcanary-response-utils
Tools to automate and/or expedite response.
DuckSysEye
SysEye是一个window上的基于att&ck现代EDR设计思想的威胁响应工具.有效检测常见的未知威胁与已知威胁.防守方的利剑
WhiteBeam
WhiteBeam: Transparent endpoint security
EDR-Test
Automating EDR Testing with reference to MITRE ATTACK via Cobalt Strike [Purple Team].
sysmon-edr
Sysmon EDR POC Build within Powershell to prove ability.