Tools/Resources
Last updated
Last updated
You dont want to use these on production servers
Mallard is my personal blue team tool written in Golang. Its main focus is on automating my 5 minute plan, and preventing new connections/sessions to the scored machine:
Awesome blue team tool created by focused on protecting scored services and maintaining persistent uptime:
For windows blue-teaming, proficiency with sysinternals really can not be beat:
Windows Defense/auditing:
Exe Dependencys:
Exe Inspector:
Exe Inspector:
Exe Inspector:
File Inspector:
Packer/Unpacker:
Metadata Viewer:
MD5 Hasher:
.NET Dissassembler/decompiler:
Dissassembler:
Dissassembler:
Hex Editor:
DNS Spoofer/ Phony DNS:
View Autorun Processes:
Process Explorer:
Process Monitor:
Windows Registry Snapshot:
TCP/IP proxy/spoofer:
Packet Sniffer:
Process Inspector:
NSA Made Decompiler:
Process pointer Inspector:
Debugger:
Debugger:
Debugger:
Snort Cheat sheet: