MindMaps icon indicating copy to clipboard operation
MindMaps copied to clipboard

#ThreatHunting #DFIR #Malware #Detection Mind Maps

MindMaps

This repository contains a collection of MindMaps that i've created

Windows System Processes

  • Svchost (Service Host Process)
  • Windows Services
  • Windows System Processes

Understanding & Detecting C2 Frameworks

  • HARS - HTTPS Asynchronous Reverse Shell (Server Handler)
  • TrevorC2 (Main Callback Flow)

Finding Detection and Forensic Goodness In ETW Providers

  • Finding Detection and Forensic Goodness In ETW Providers

ETW Providers

  • TBD

Visualize

Currently the Mind Maps are only available in ".xmind" format. You can visualize them using XMind or by importing them into EdrawMind