  • atomic-red-team

    Small and highly portable detection tests based on MITRE's ATT&CK.

    Project mention: Attack simulation tool based on CVE | reddit.com/r/redteamsec | 2022-10-06

    A lot of tools exist for testing and it depends on what you want to test for which is the right thing. MITRE Atomic Red Team for example will test via PowerShell on a SOE, https://github.com/redcanaryco/atomic-red-team and includes payloads that it calls over the network from GitHub for example.

  • sysmon-modular

    A repository of sysmon configuration modules

    Project mention: Is Windows Defender for Business any good? | reddit.com/r/cybersecurity | 2022-11-09

    Agree. Harden your endpoints (if unsure where to start consider hardening kitty, https://github.com/scipag/HardeningKitty) and harden Defender (https://0ut3r.space/2022/03/06/windows-defender/). Add Sysmon with a good config (https://github.com/olafhartong/sysmon-modular) and you've reached a good starting point.

PowerShell mitre-attack related posts


