Code Monkey home page Code Monkey logo

Hi there šŸ‘‹ here is a overview of my OSS.

About Me:

  • šŸ”­ Iā€™m currently working on offensive modules for Quasar Rat (CSharp)
  • šŸŒ± Iā€™m currently learning predictive search techniques (Python)
  • šŸ‘Æ Iā€™m looking to collaborate on anything fun/new/cool
  • šŸ“« How to reach me: [email protected]
  • āš” Fun fact: I'll get back to you on this one.....

āš” Cyber Security Research & Tools

Over the years I have worked on various projects ranging from small research projects to team based projects in support of OSS. The following work spans over 10 years of OSS development, training, and research. Most of the code is research for other operational projects for cyber threat hunting, red teaming, pentesting, and IR.

šŸŒ± Courses Authored

  • SOC Immersion Training (SIT) - (2018) Co-Author, SIT is designed for intermediate-level cybersecurity and hunt team analysts to increase their functional knowledge of analytical thinking and concepts. By using demonstrated real-world attack methodologies in a step-by-step manner, SIT provides analysts with an in-depth understanding of how to analyze attack TTPs and the ability to construct complex IOCs derived from environment-specific threats and constraints.

šŸ’¬ Confrence Talks & Research

Red Team Infrastructure
Cyber Security Scripts/Tools
  • BRO - Network Security Monitoring - Collection of Bro and bash scripts that when run from the same directory on a Linux distro with bro installed; will pull information such as active HTTP conns, FTP conns, DNS Request/Responses, And a live(-20 seconds) feed for files transmitted. It also carves the various types of files at the same time. They can be run against snort logs or pcaps.
  • NodeHunter - Python wrapper around NMAP api to perform quick and dirty node and service discovery and enumeration.
  • CS-Beacon-Detector - (2015) Custom Sniffer that was designed to work against Cobal Strike DNS Beacons. It listens for DNS beacons and analyzes the URL, Request, and multiple specific fields within the payload. It performs some correlation to determine the validity of requests and replies.
  • DNShunter - DNShunter is a python based module that is written for a Hunt Framework & custom Linux distro built for hunt operations. Currently it reads in .pcap files and extracts the DNS Queries and Answers. In addition to extracting the queries & answers, it also performs a geo-lookup of the domains & the associated IP's.
  • S3 - Splunk Sexy Six - Open Source Windows Security Event Log Correlation and Analysis Tool
  • VDNS - VDNS is a python application that parses Bro's dns.log file and injests the results into the neo4j database for visual analysis
  • OFF-ToolKit - Project created to gather host based forensic data to later use during an offensive engagement
  • NetInfo - Quick and dirty python script to gather network information from windows registry.
Agents

Keelyn Roberts's Projects

basic_rpc icon basic_rpc

Samples about Microsoft RPC and native API calls in Windows C

breadplayer icon breadplayer

Bread Player, a free and open source music player powered by UWP and C#/.NET with a sleek and polished design built for, and by, the people seeking a better alternative to Groove and Windows Media Player by Microsoft.

bro-networksecuritymonitoring icon bro-networksecuritymonitoring

collection of bro and bash scripts that when run from the same directory on Linux distro with bro installed, will pull information such as active HTTP conns, FTP conns, etc. It also carves various types of files at the same time. They can be run against snort logs or pcaps

cpprestsdk icon cpprestsdk

The C++ REST SDK is a Microsoft project for cloud-based client-server communication in native code using a modern asynchronous C++ API design. This project aims to help C++ developers connect to and interact with services.

cs-beacon-detector icon cs-beacon-detector

Custom Sniffer that listens for DNS beacons and analyzes the validity of alerts

dnshunter icon dnshunter

DNShunter is a python based module that is written for MercenaryHuntFramework & Mercenary-Linux. Currently it reads in .pcap files and extracts the DNS Queries and Answers. In addition to extracting the queries & answers, it also performs a geo-lookup of the domains & the associated IP's. This makes it easy to catch attacks such as DNS Cache Poisoning and DNSBeacons. EX: [Q] firstnationalbank.com -> resolving to Indonesia

dnsjsonparser icon dnsjsonparser

custom JSON parser that parses the json output created by chopshop's (dns & dns_extractor) modules

gephi-plugins icon gephi-plugins

Repository for Gephi Plugins maintained by the team. Each plugin has it's branch.

greatfet icon greatfet

Experimental GreatFET firmware and software

hale icon hale

Botnet command & control monitor

kekeo icon kekeo

A little toolbox to play with Microsoft Kerberos in C

mimikatz icon mimikatz

A little tool to play with Windows security

nodehunter icon nodehunter

Python Module that uses the NMAP api to enumerate a network and its hosts.

off-toolkit icon off-toolkit

Framework for Registry Based Artifact Collection and Correlation

quasar icon quasar

Remote Administration Tool for Windows

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    šŸ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. šŸ“ŠšŸ“ˆšŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ā¤ļø Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.