BLUESPAWN icon indicating copy to clipboard operation
BLUESPAWN copied to clipboard

An Active Defense and EDR software to empower Blue Teams

Results 31 BLUESPAWN issues
Sort by recently updated
recently updated
newest added

Just a heads up. VT score of 3/68. Likely a false positive due to incorporation of Atomic tests. Given the value of this project though, it would be good to...

type/bug
priority/high
difficulty/hard

in progress
difficulty/hard
lang/c++

once the docs get merged into develop

type/enhancement
difficulty/easy

type/enhancement
difficulty/easy

https://github.com/Imanfeng/Telemetry https://www.trustedsec.com/blog/abusing-windows-telemetry-for-persistence/

type/enhancement
module/configuration
priority/high
module/file-system
difficulty/easy
lang/c++
mode/hunt
platform/client

https://github.com/gtworek/PSBits/tree/master/PasswordStealing/NPPSpy

type/enhancement
module/configuration
module/file-system
difficulty/easy
lang/c++
mode/hunt
platform/client

https://attack.mitre.org/techniques/T1546/002/ https://attack.mitre.org/techniques/T1547/003/ https://attack.mitre.org/techniques/T1197/

type/enhancement
priority/low
in progress
difficulty/easy
lang/c++
mode/monitor
mode/hunt

https://docs.rapid7.com/insightidr/windows-suspicious-process

"detect netbios/LLMNR poisoning by having your endpoint agent issue a request for a non-existent resource. Tools like Responder would respond to this request, giving themselves away. I can say from...

type/enhancement
module/configuration
difficulty/hard
lang/c++
mode/hunt
platform/client

type/enhancement
priority/high
difficulty/hard
lang/c++
platform/client
integration/agent7