Extract DPAPI-protected secrets such as credentials and browser data offline and online.
日本語の概要は準備中です。原文の説明を表示しています。
Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics. Identifies after-hours bulk downloads, access from new IP addresses, unusual API calls (GetObject spikes), and potential data exfiltration using statistical baselines and time-series anomaly detection.
インストールする前に、エージェントに与えられる指示の中身を確認できます。
pip install boto3 requestspython scripts/agent.py --bucket my-sensitive-data --hours-back 24 --output s3_access_report.json
{"eventName": "GetObject", "requestParameters": {"bucketName": "sensitive-data", "key": "financials/q4.xlsx"},
"sourceIPAddress": "203.0.113.50", "userIdentity": {"arn": "arn:aws:iam::123456789012:user/analyst"}}
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Extract DPAPI-protected secrets such as credentials and browser data offline and online.
日本語の概要は準備中です。原文の説明を表示しています。
Audit, detect, and remediate Shadow Credentials misconfigurations on msDS-KeyCredentialLink in Active Directory. Focuses on access-controls, monitoring Event ID 5136, and credential-management hygiene.
日本語の概要は準備中です。原文の説明を表示しています。
Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, manage a compliant POA&M, and ready the organization for a C3PAO assessment. Use when an organization handles Controlled Unclassified Information (CUI) under a DoD contract, when a contract carries DFARS clause 252.204-7012/7019/7020/7021, when preparing for or responding to a CMMC assessment, when computing or improving an SPRS score, when building a System Security Plan or POA&M for 800-171, or when scoping which systems are in the CUI boundary. Keywords: CMMC, CMMC Level 2, NIST 800-171, SP 800-171 Rev 2, CUI, FCI, SPRS, DFARS 7012, C3PAO, POA&M, System Security Plan, DoD Assessment Methodology, 110 controls, defense industrial base, DIB, FedRAMP equivalency.
日本語の概要は準備中です。原文の説明を表示しています。
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash verification.
日本語の概要は準備中です。原文の説明を表示しています。
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and WriteOwner abuse paths
日本語の概要は準備中です。原文の説明を表示しています。
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source recovery, and androguard for permission analysis, manifest inspection, and suspicious API call detection.
日本語の概要は準備中です。原文の説明を表示しています。