My Security Intelligence and Monitoring Agenda List

1 Project[Reorg]

2 Silk

3 Osquery

4 Mitre&ATT

  1. Experts advocate for ’ATT&CK’ as go-to framework to share threat intel
  2. Cyber Wardog Lab: How Hot Is Your Hunt Team?
  3. BlueTeamToolkit/sentinel-attack: Repository of sentinel alerts and hunting queries leveraging sysmon and the MITRE ATT&CK framework

5 ELK

5.2 Logstash

  1. Filter   Nettoolset
    1. ✔ DONE Urldecode <2018-06-07 Thu>
      • State “DONE” from [2018-06-07 Thu 14:21]

      手机淘宝/3442425 CFNetwork/897.15 Darwin/17.5.0

      1. Link
    2. fv<2018-06-07 Thu>
      1. link

6 thesis

:PROPERTIES: academia :CATEGORY: thesis

6.1 1808.10742.pdf [Anomaly Detection in Cyber Network Data Using a Cyber Language Approach]

6.4 HTTP

  1. DeepHTTP: Semantics-Structure Model with Attention for Anomalous HTTP Traffic Detection and Pattern Mining
  2. [[https://blog.csdn.net/qq_30050175/article/details/90577778][DECANTeR: DEteCtion of Anomalous outbouNd HTTP TRaffic by Passive Application Fingerprinting - 一只咸鱼的小努力 - CSDN

7 Con & Video & Documention

7.5 Botconf

  1. Olivier Bilodeau https://www.youtube.com/watch?v=iW-WmhPu6p4

7.6 Sans

  1. [Botnet Tracking Tools ] [] https://www.youtube.com/watch?v=iW-WmhPu6p4

7.7 WAITING Traffic filtering at scale on Linux   Document NSM

  • State “WAITING” from [2018-11-06 Tue 12:44]

7.9 bro-2.4.1.pdf Document:

7.13 d1s1r4.pdf PPT:

8 Repo

8.2 https://scrapy.org/   spider

8.3 JohnLaTwC (John Lambert) [Distinguished Engineer and General Manager, Microsoft Threat Intelligence Center]

9 Logs query

10 Data visualization

11 pwn

12 Owncloud   NSM

 curl -u ghost:own@321 -T "/Users/gtrun/org-notes/NsmOrg.org" "http://192.168.1.100/owncloud/remote.php/webdav/org-notes/NsmOrg.org"
curl -u ghost:own@321 -O http://192.168.1.100/owncloud/remote.php/webdav/org-notes/NsmOrg.org
sshpass -p "123" scp /Users/gtrun/org-notes/NsmOrg.org 192.168.1.9:~/org-notes/.

sudo bro -r tests/traces/http-get-large-incomplete.pcap tests/scripts/file-analyzer.bro

13 OSINT

14 MITRE

15 Sandbox

16 Data

17 memo

17.3 bagder (Daniel Stenberg)   NETWORK

18 SOC Platforms

18.5 ✘ CANCELED crits/crits: CRITs - Collaborative Research Into Threats

  • State “✘ CANCELED” from [2019-09-07 Sat 17:45]

19 [A] Cache

19.5 ✰ Important My Software | Didier Stevens

20 Tor

21 https://github.com/willemt/py2graphql

Created: 2021-01-03 Sun 20:03

Emacs 28.0.50 (Org mode 9.5)