• Stars
    star
    127
  • Rank 282,790 (Top 6 %)
  • Language
    Shell
  • License
    GNU General Publi...
  • Created over 4 years ago
  • Updated over 3 years ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

Cloud Templates and scripts to deploy mordor environments

SimuLand 🏝️

Open_Threat_Research Community Open Source Love

An initiative from the Open Threat Research (OTR) community to share cloud templates and scripts to deploy network environments to simulate adversaries, generate/collect data and learn more about adversary tradecraft from a defensive perspective. The difference with other environments is that we do not have one scenario to cover all use-cases, but multiple modular environments that adapt to specific topics of research.

Think of this repository as the library of emulation/simulation plans but from an infrastructure perspective 🏗️

We started by sharing ATT&CK evaluations environment templates with the community (i.e APT29 Scenario). Now we are expanding our scope and building more templates for other projects such as:

Finally, we do not only create these environments for someone to follow an attack path and execute it, but also to collect and share telemetry. Every environment built under the project SimuLand has a data pipeline to export the data collected during the simulation and share it with the community officially through the Mordor Project.

Author

Roberto Rodriguez @Cyb3rWard0g

More Repositories

1

ThreatHunter-Playbook

A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
Python
3,964
star
2

Security-Datasets

Re-play Security Events
PowerShell
1,582
star
3

OSSEM

Open Source Security Events Metadata (OSSEM)
Python
1,232
star
4

ATTACK-Python-Client

Python Script to access ATT&CK content available in STIX via a public TAXII server
Python
554
star
5

Microsoft-Sentinel2Go

Microsoft Sentinel2Go is an open source project developed to expedite the deployment of a Microsoft Sentinel research lab.
PowerShell
540
star
6

Blacksmith

Building environments to replicate small networks and deploy applications
PowerShell
317
star
7

OSSEM-DM

OSSEM Detection Model
Python
164
star
8

detection-hackathon-apt29

Place for resources used during the Mordor Detection hackathon event featuring APT29 ATT&CK evals datasets
Jupyter Notebook
130
star
9

infosec-jupyter-book

The Infosec Community Definitive Guide to Jupyter Notebooks
Dockerfile
107
star
10

infosec-jupyterthon

A community event for security researchers to share their favorite notebooks
Jupyter Notebook
105
star
11

GenAI-Security-Adventures

Jupyter Notebook
93
star
12

Set-AuditRule

Useful access control entries (ACE) on system access control list (SACL) of securable objects to find potential adversarial activity
PowerShell
86
star
13

notebooks-forge

A collection of notebooks built for defensive and offensive operations.
Jupyter Notebook
76
star
14

API-To-Event

A repo to document API functions mapped to security events across diverse platforms
74
star
15

OSSEM-DD

OSSEM Data Dictionaries
Python
56
star
16

OSSEM-CDM

OSSEM Common Data Model
54
star
17

bloodhound-notebook

BloodHound Cypher Queries Ported to a Jupyter Notebook
Python
53
star
18

openhunt

Python
33
star
19

bloodhound-notebooks

Notebooks created to attack and secure Active Directory environments
Jupyter Notebook
27
star
20

SANS-BlueTeamSummit-2022

Repo to track SANS BlueTeam Summit Presentation
Jupyter Notebook
23
star
21

2021-OceanLotus-workshop

HCL
18
star
22

BHEU22-ADFS

Writing Your Own Ticket to the Cloud Like APT: A Deep-dive to AD FS Attacks, Detections, and Mitigations
12
star
23

MEAN

Microsoft Entra ID Administration LLM-based Autonomous Agent
Jupyter Notebook
8
star
24

docker-c2

Docker files used to deploy known Command & Control (C2) Frameworks
5
star
25

workshop-ekoparty-bluespace-2020

Materiales para enseñar lo básico de Jupyter Notebooks y análisis de data con Pandas
Dockerfile
3
star
26

OpenSec-Library

2
star
27

Blog-Website

Official OTR Blog Website
2
star
28

Infosec-DMZ

1
star
29

OSSEM-DD-MASK

An extension of the OSSEM-DD repository.
1
star
30

Community-Presentations

Slides
1
star