Skip to content
View mthcht's full-sized avatar
🏠
Working from home
🏠
Working from home

Highlights

  • Pro

Organizations

@s1community @lolc2 @BADGUIDS @sinkholed @lolexfil

Block or report mthcht

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Living of the Land of Free SaaS

HTML 63 2 Updated Mar 22, 2026

TRAM is an open-source platform designed to advance research into automating the mapping of cyber threat intelligence reports to MITRE ATT&CK®.

Jupyter Notebook 555 109 Updated May 6, 2025

Living off the land Data Exfiltration methods

HTML 45 8 Updated Mar 23, 2026
HTML 18 1 Updated Mar 15, 2026

Docs and samples for privileged identity and access management in Microsoft Azure and Microsoft Entra.

PowerShell 185 35 Updated Mar 23, 2026

A collection of Azure AD/Entra tools for offensive and defensive security purposes

Python 2,559 363 Updated Feb 5, 2026

Red team tool for abusing Commvault to achieve lateral movement, persistence, and file collection.

C# 7 1 Updated Sep 9, 2025

This project aims to be a drop-in replacement for the certstream server by Calidog. This tool aggregates, parses, and streams certificate data from multiple certificate transparency logs via websoc…

Go 197 36 Updated Mar 23, 2026

A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

PowerShell 916 88 Updated Jan 15, 2026

VECTR is a tool that facilitates tracking of your red and blue team testing activities to measure detection and prevention capabilities across different attack scenarios

1,555 179 Updated Mar 12, 2026

Public repository of Sigma and YARA rules created by Synacktiv

YARA 18 1 Updated Oct 15, 2025

Sublime rules for email attack detection, prevention, and threat hunting.

YAML 352 92 Updated Mar 24, 2026

Public static website for the D3FEND project. For the D3FEND ontology repo see: https://github.com/d3fend/d3fend-ontology

HTML 90 19 Updated Dec 16, 2025

Stakeholder-Specific Vulnerability Categorization

Python 177 43 Updated Mar 23, 2026

A knowledge base of actionable Incident Response techniques

Python 663 121 Updated May 31, 2022

TheHive is a Collaborative Case Management Platform, now distributed as a commercial version

Scala 3,897 684 Updated Jul 25, 2025

MCP Server for Ghidra

Java 8,038 735 Updated Jun 23, 2025

Matkap - hunt down malicious Telegram bots

Python 928 160 Updated Aug 11, 2025

Resolving sinkholed domains

HTML 6 Updated Mar 7, 2025

Threat-hunting tool for Linux

Rust 1,046 74 Updated Mar 24, 2026

Small and highly portable detection tests based on MITRE's ATT&CK.

C 11,726 3,079 Updated Mar 24, 2026
C++ 31 5 Updated Feb 28, 2025

Splunk Content Control Tool

Python 130 44 Updated Mar 5, 2026

Block file creation with use of eBPF

C 5 2 Updated Feb 21, 2025

FJTA (Forensic Journal Timeline Analyzer) is a tool that analyzes Linux filesystem (ext4, XFS) journals (not systemd-journald logs), generates timelines, and detects suspicious activities.

Python 104 9 Updated Jan 13, 2026

Windows kernel and user mode emulation.

Python 1,903 282 Updated Mar 24, 2026

A tool for checking if MFA is enabled on multiple Microsoft Services

PowerShell 1,640 228 Updated Mar 4, 2025

This repository is for Indicators of Compromise (IOCs) from Zscaler ThreatLabz public reports

YARA 78 15 Updated Jan 26, 2026

A Python reference implementation for CZDS download zone file API

Python 127 49 Updated Apr 2, 2025
Python 775 115 Updated May 7, 2025
Next