BLUESPAWN
BLUESPAWN copied to clipboard
An Active Defense and EDR software to empower Blue Teams
Just a heads up. VT score of 3/68. Likely a false positive due to incorporation of Atomic tests. Given the value of this project though, it would be good to...
once the docs get merged into develop
https://github.com/Imanfeng/Telemetry https://www.trustedsec.com/blog/abusing-windows-telemetry-for-persistence/
https://github.com/gtworek/PSBits/tree/master/PasswordStealing/NPPSpy
https://attack.mitre.org/techniques/T1546/002/ https://attack.mitre.org/techniques/T1547/003/ https://attack.mitre.org/techniques/T1197/
https://docs.rapid7.com/insightidr/windows-suspicious-process
"detect netbios/LLMNR poisoning by having your endpoint agent issue a request for a non-existent resource. Tools like Responder would respond to this request, giving themselves away. I can say from...