Файл
MITRE ATTACKS DETECTION RULES PART1.pdf · 2.2 МБ · нажмите — покажем
MITRE ATTACKS DETECTION RULES PART1.pdf · 2.2 МБ · нажмите — покажем
MITRE ATTA&CK Detection Rules Part 1
@BlueTeamKit
115 · 5.3K · Файл
MITRE ATTACKS DETECTION RULES PART2.pdf · 2.7 МБ · нажмите — покажем
MITRE ATTACKS DETECTION RULES PART2.pdf · 2.7 МБ · нажмите — покажем
MITRE ATTA&CK Detection Rules Part 2
@BlueTeamKit
116 · 5.7K · Видео
Blue Team Full Course - From Beginner to Job-Ready.mp4 · 229.9 МБ · нажмите — покажем
Blue Team Full Course - From Beginner to Job-Ready.mp4 · 229.9 МБ · нажмите — покажем
Blue Team Full Course - From Beginner to Job-Ready
@BlueTeamKit
110 · 6.2K · Файл
Windows Event Log Analysis & IR Guide .pdf · 602 КБ · нажмите — покажем
Windows Event Log Analysis & IR Guide .pdf · 602 КБ · нажмите — покажем
Windows Event Log Analysis & IR Guide
@BlueTeamKit
130 · 6.2K · Blue Team
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
🚨 Most SOC teams do not have a data problem.
They have a decision-speed problem.
Modern SIEM platforms already collect enormous volumes of telemetry from endpoints, identities, networks, cloud environments, and applications.
The challenge is turning that data into a reliable answer before an attacker reaches the next stage of the attack.
That is where AI is beginning to change security operations.
@BlueTeamKit
52 · 4K · Blue Team
Файл
PLM_NIDS.pdf · 929 КБ · нажмите — покажем
PLM_NIDS.pdf · 929 КБ · нажмите — покажем
PLM-NIDS: A Protocol-Language Model for Network Intrusion Detection from Raw Packet Sequences Using RWKV State-Space Models
]-> https://github.com/shiva2vk/PLM-NIDS
// The RWKV backbone’s O(T) recurrent inference enables per-packet streaming without flow buffering, making PLM-NIDS operationally viable at line rate. Because it reads only IP/TCP/UDP headers, it is inherently encryption-agnostic: TLS 1.3, QUIC, and future encrypted protocols are handled transparently
@BlueTeamKit
33 · 4.2K · Blue Team
Ссылка
нажмите — покажем
нажмите — покажем
EDR-Redir : a tool used to redirect the EDR's folder to another location.
https://github.com/TwoSevenOneT/EDR-Redir
@BlueTeamKit
27 · 4.5K · Blue Team
Файл
PowerShell Hunting & Detection.pdf · 841 КБ · нажмите — покажем
PowerShell Hunting & Detection.pdf · 841 КБ · нажмите — покажем
PowerShell Hunting & Detection
@BlueTeamKit
45 · 2.4K · Blue Team
Файл
Splunk Use Cases.pdf · 2.2 МБ · нажмите — покажем
Splunk Use Cases.pdf · 2.2 МБ · нажмите — покажем
Splunk Use Cases
@BlueTeamKit
31 · 1.1K · Blue Team
Файл
Redline Stealer - HUNTER Emerging Threats.pdf · 81 КБ · нажмите — покажем
Redline Stealer - HUNTER Emerging Threats.pdf · 81 КБ · нажмите — покажем
Redline Stealer - HUNTER Emerging Threats
@BlueTeamKit
18 · 807 · Файл
Threat Hunting Principles (Windows).pdf · 5.1 МБ · нажмите — покажем
Threat Hunting Principles (Windows).pdf · 5.1 МБ · нажмите — покажем
Windows Threat Hunting
@BlueTeamKit
27 · 814 · Файл
Hands-On MCP Security Bootcamp.mp4 · 191.1 МБ · нажмите — покажем
Hands-On MCP Security Bootcamp.mp4 · 191.1 МБ · нажмите — покажем
Hands-On MCP Security Bootcamp
@BlueTeamKit
20 · 746 · Blue Team
Ссылка
нажмите — покажем
нажмите — покажем
DFIR Tools for Capturing RAM/Memory Forensics
1. Belkasoft RAM Capturer: https://belkasoft.com/ram-capturer
2. WinPmem: https://github.com/Velocidex/WinPmem
3. Magnet RAM Capture: https://www.magnetforensics.com/resources/magnet-ram-capture/
4. Sumuri Recon ITR: https://sumuri.com/software/recon-itr/
5. Cellebrite Digital Collector: https://cellebrite.com/en/digital-collector/
6. Volatility: https://volatilityfoundation.org/the-volatility-framework/
7. MemProcFS: https://github.com/ufrisk/MemProcFS
8. Magnet DumpIt: https://www.magnetforensics.com/resources/magnet-dumpit-for-windows/
9. LiME: https://github.com/504ensicsLabs/LiME
@BlueTeamKit
15 · 219 ·