nicodemus
EnterprisePurpleTeaming
nicodemus | EnterprisePurpleTeaming | |
---|---|---|
1 | 6 | |
31 | 622 | |
- | - | |
0.0 | 3.3 | |
over 2 years ago | 11 months ago | |
Nim | ||
GNU General Public License v3.0 only | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
nicodemus
EnterprisePurpleTeaming
-
Tool for Creating Randomized IR Scenarios
You might want to look at platforms like Scythe and into purple teaming in general. Aside from that quite the number of projects involving attack simualtion on atomic level using caldera or atomic red team. Another great resource: https://github.com/ch33r10/EnterprisePurpleTeaming
-
Analysing attacks from a Blue team perspective
As you are about to purpleteam yourself, Xena Olsen got you covered with a lot of great resources and a stuctured methodic approach: https://github.com/ch33r10/EnterprisePurpleTeaming Above that, when using Splunk you most probably had a look at the boss of the soc datasets - prequalified/-recorded close2real attack data which will assist in getting the hang of being able to discern the good from the bad; on a side note - with Splunk now pubicly sharing their security content (=use cases) you have another source to check out the level of correlation and most importantly the context information needed to make a decision. Context is everything - only by having all the facts you'll be able to tell whether that shadow copy deletion came from the backup agent or your friendly neighborhood ransom gang.
-
Need help with Red Team PoC setup/demo
Dr. Xena has got you covered - check tool section: https://github.com/ch33r10/EnterprisePurpleTeaming
- EnterprisePurpleTeaming: Purple Team Resources for Enterprise Purple Teaming: An Exploratory Qualitative Study. Doctor of Science Cybersecurity at Marymount University Dissertation by Xena Olsen.
- GitHub - ch33r10/EnterprisePurpleTeaming: Purple Team Resources for Enterprise Purple Teaming: An Exploratory Qualitative Study. Doctor of Science Cybersecurity at Marymount University Dissertation by Xena Olsen.
-
Enterprise Purple Team Doctoral Research Call for Participants
Here's an Enterprise Purple Team resource (I will continue adding items): https://github.com/ch33r10/EnterprisePurpleTeaming
What are some alternatives?
Nim - Nim is a statically typed compiled systems programming language. It combines successful concepts from mature languages like Python, Ada and Modula. Its design focuses on efficiency, expressiveness, and elegance (in that order of priority).
caldera - Automated Adversary Emulation Platform
community - All open-source content for the Prelude Operator C2 platform
sliver - Adversary Emulation Framework
OffensiveNim - My experiments in weaponizing Nim (https://nim-lang.org/)
pwnspoof - Pwnspoof repository
Nimbo-C2 - Nimbo-C2 is yet another (simple and lightweight) C2 framework
purple-team-exercise-framework - Purple Team Exercise Framework
SecGen - Create randomly insecure VMs
slack-watchman - Slack enumeration and exposed secrets detection tool