{"id":33245392,"url":"https://github.com/ch33r10/BlueSpace2021","last_synced_at":"2026-03-29T21:00:45.807Z","repository":{"id":134653054,"uuid":"409056767","full_name":"ch33r10/BlueSpace2021","owner":"ch33r10","description":"Ekoparty's BlueSpace Keynote November 2021. Shoutout to @plugxor Muchas Gracias!!!","archived":false,"fork":false,"pushed_at":"2023-06-05T03:06:43.000Z","size":13413,"stargazers_count":12,"open_issues_count":0,"forks_count":2,"subscribers_count":1,"default_branch":"main","last_synced_at":"2024-01-29T09:42:41.866Z","etag":null,"topics":["cti","cyber-threat-hunting","cyber-threat-intelligence","hunt","hunting","threat-hunting","threat-intel","threat-intelligence"],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ch33r10.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null}},"created_at":"2021-09-22T03:51:43.000Z","updated_at":"2023-08-23T10:27:18.000Z","dependencies_parsed_at":null,"dependency_job_id":"3b120337-32fa-440d-9dc2-a48a7cc09bf3","html_url":"https://github.com/ch33r10/BlueSpace2021","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/ch33r10/BlueSpace2021","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ch33r10%2FBlueSpace2021","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ch33r10%2FBlueSpace2021/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ch33r10%2FBlueSpace2021/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ch33r10%2FBlueSpace2021/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ch33r10","download_url":"https://codeload.github.com/ch33r10/BlueSpace2021/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ch33r10%2FBlueSpace2021/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":31164979,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-29T18:55:37.765Z","status":"ssl_error","status_checked_at":"2026-03-29T18:55:04.089Z","response_time":89,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["cti","cyber-threat-hunting","cyber-threat-intelligence","hunt","hunting","threat-hunting","threat-intel","threat-intelligence"],"created_at":"2025-11-16T21:00:32.225Z","updated_at":"2026-03-29T21:00:45.801Z","avatar_url":"https://github.com/ch33r10.png","language":null,"funding_links":[],"categories":["Blue Team"],"sub_categories":["Threat Hunting"],"readme":"# [![BlueSpace2021 header](https://github.com/ch33r10/BlueSpace2021/blob/main/rock/paint_it_blue.jpg)](https://sites.google.com/view/ch33r10/me)\n\u003cp align='center'\u003e\n\u003ca href=\"https://twitter.com/Ch33r10\"\u003e\u003cimg height=\"30\" src=\"https://github.com/ch33r10/BlackHatAsia2020/blob/master/img/twitter%20blue%20logo.png\"\u003e\u003c/a\u003e\n \u003ca href=\"https://www.linkedin.com/in/xena-olsen/\"\u003e\u003cimg height=\"30\" src=\"https://github.com/ch33r10/BlackHatAsia2020/blob/master/img/linkedin%20logo.png\"\u003e\u003c/a\u003e\n\u003c/p\u003e\n\u003ch3 align=\"center\"\u003ePAINT IT, BLUE Slides - \u003ca href=\"https://github.com/ch33r10/BlueSpace2021/blob/main/rock/Talk_2021_Paint_it_Blue.pdf\"\u003eLink\u003c/a\u003e\u003c/h3\u003e\n\n\u003cp align=\"center\"\u003ePro Tips on transitioning from CTI to Hunt\u003c/p\u003e\n\u003chr\u003e\u003c/hr\u003e\n\u003cp\u003e\u003ch1 align=\"center\"\u003e🎸\u003cb\u003eRESEARCH\u003c/b\u003e\u003c/h1\u003e\u003c/p\u003e\n \u003cp\u003e\u003c/p\u003e\n\u003ch3 align=\"left\"\u003e🥁\u003cb\u003eGOAL = ASK BETTER QUESTIONS\u003c/b\u003e\u003c/h3\u003e\n\n**SOCIAL MEDIA \u0026 MORE**|**SANS**|**WORKSHOPS / TALKS**|**DISCORDS / SLACKS**\n---|---|---|---\n#HuntingTipOfTheDay, Follow Threat Hunting Accounts EVERYWHERE - \u003ca href=\"https://twitter.com/i/lists/1445402146434867206\"\u003eLink\u003c/a\u003e|Reading Room - \u003ca href=\"https://www.sans.org/white-papers/\"\u003eLink\u003c/a\u003e, Webcasts - \u003ca href=\"https://www.sans.org/webcasts/\"\u003eLink\u003c/a\u003e \u0026 Threat Hunting Summit|Prioritize Threat Hunting Talks/Workshops \u0026 take a look at YouTube|Join Slack/Discord related to infosec (BlueSpace has a Discord Channel - \u003ca href=\"invite.gg/bluespace\"\u003eLink\u003c/a\u003e)\n\u003cp\u003e\u003c/p\u003e\n\u003ch3 align=\"left\"\u003e📝\u003cb\u003eCH33R10'S TALK NOTES EXAMPLE\u003c/b\u003e\u003c/h3\u003e\n\u003csub\u003eI have a folder where I create a document for each conference. \n I list the name of the talk or workshop and while watching I will take screenshots, if it is allowed, of the slides and make notes that I can reference later. Any words in the slides that I want to makes sure are searchable, I will type the keywords below the slides. I grab whatever links the speaker(s) share that I can. I make sure to highlight my personal takeaways or takeaways that I feel could be valuable for someone else. I make a point to include things I am curious about regardless of how weird/off-the-wall/impractical my questions/thoughts may be.\u003c/sub\u003e \n\u003cp\u003e\u003c/p\u003e\nTEXAS CYBER SUMMIT 2021\n\u003cul\u003e\n \u003cli\u003eBecoming a Threat Hunter: This Is One Way by Jason Wood - \u003ca href=\"https://youtu.be/na1PBrWvJjY\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cul\u003e\u003cli\u003e\u003cB\u003eLINKS\u003c/B\u003e\u003c/li\u003e\u003c/ul\u003e\n \u003cul\u003e\u003cul\u003e\u003cli\u003eCrowdstrike Global Threat Report 2021 - \u003ca href=\"https://www.crowdstrike.com/resources/reports/global-threat-report/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/ul\u003e\n  \u003cul\u003e\u003cul\u003e\u003cli\u003eCrowdstrike Threat Hunting Report 2021 - \u003ca href=\"https://www.crowdstrike.com/resources/reports/threat-hunting-report-2021/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/ul\u003e\n  \u003cul\u003e\u003cul\u003e\u003cli\u003eDetection Lab by Chris Long - \u003ca href=\"https://github.com/clong/DetectionLab\"\u003eLink\u003c/a\u003e\u003c/ul\u003e\u003c/ul\u003e\u003c/li\u003e\n  \u003cp\u003e\u003c/p\u003e\n  \u003cul\u003e\u003cli\u003e\u003cB\u003eTALK TAKEAWAYS\u003c/B\u003e\u003c/ul\u003e\u003c/li\u003e\n  \u003csub\u003eI took a screenshot of Jason Wood's slide for my personal notes that I retyped below. These are his words on the slide that I duplicated. All credit for the words on the slide goes to Jason Wood. This duplication is for educational purposes.\u003c/sub\u003e\u003cp\u003e\u003c/p\u003e\n \u003cul\u003e\u003cul\u003e\u003cli\u003eDocument your Practice\u003c/ul\u003e\u003c/ul\u003e\u003c/li\u003e\n \u003cul\u003e\u003cul\u003e\u003cul\u003e\u003cli\u003eRecord videos and publish them\u003c/ul\u003e\u003c/ul\u003e\u003c/ul\u003e\u003c/li\u003e\n \u003cul\u003e\u003cul\u003e\u003cul\u003e\u003cli\u003eWrite up your learning experience\u003c/ul\u003e\u003c/ul\u003e\u003c/ul\u003e\u003c/li\u003e\n \u003cul\u003e\u003cul\u003e\u003cul\u003e\u003cli\u003eGive a conference presentation\u003c/ul\u003e\u003c/ul\u003e\u003c/ul\u003e\u003c/li\u003e\n \u003cul\u003e\u003cul\u003e\u003cul\u003e\u003cli\u003eDocument how you hunt at work\u003c/ul\u003e\u003c/ul\u003e\u003c/ul\u003e\u003c/li\u003e\n \u003cul\u003e\u003cul\u003e\u003cul\u003e\u003cul\u003e\u003cli\u003eDon't publish external. Keep it inside your employer\u003c/ul\u003e\u003c/ul\u003e\u003c/ul\u003e\u003c/ul\u003e\u003c/li\u003e\n  \u003cul\u003e\u003cul\u003e\u003cul\u003e\u003cli\u003eBenefits of documenting\u003c/ul\u003e\u003c/ul\u003e\u003c/ul\u003e\u003c/li\u003e\n   \u003cul\u003e\u003cul\u003e\u003cul\u003e\u003cul\u003e\u003cli\u003eHelps you talk about it in interviews\u003c/ul\u003e\u003c/ul\u003e\u003c/ul\u003e\u003c/ul\u003e\u003c/li\u003e\n    \u003cul\u003e\u003cul\u003e\u003cul\u003e\u003cul\u003e\u003cli\u003eCan talk about how you've applied it at work\u003c/ul\u003e\u003c/ul\u003e\u003c/ul\u003e\u003c/ul\u003e\u003c/li\u003e\n   \u003cp\u003e\u003c/p\u003e\n \u003cul\u003e\u003cli\u003e\u003cB\u003eCh33r10's RANDOM THOUGHTS \u0026 QUESTIONS\u003c/B\u003e\u003c/ul\u003e\u003c/li\u003e\n \u003cul\u003e\u003cul\u003e\u003cli\u003eI wonder if it is possible to use Chris Long's Detection Lab with the tools shared in the Busting the Ghost in the Logs talk by Randy Pargman \u0026 Jean-Francois Maes during Texas Cyber Summit 2021 - \u003ca href=\"https://youtu.be/bTU5xTIXoI4\"\u003eLink\u003c/a\u003e\u003c/ul\u003e\u003c/ul\u003e\u003c/li\u003e\n \u003cul\u003e\u003cul\u003e\u003cli\u003eI wonder how Chris Long's Detection Lab compares with Splunk's Attack Range\u003c/ul\u003e\u003c/ul\u003e\u003c/li\u003e\n \u003cul\u003e\u003cul\u003e\u003cli\u003eI wonder how I can take my threat hunting practice to the next level and make my practice more organization relevant, such as tooling, telemetry, honeypots? etc\u003c/ul\u003e\u003c/ul\u003e\u003c/li\u003e\n\u003cul\u003e\u003cul\u003e\u003cul\u003e\u003cli\u003eI wonder if it is possible to obtain a researcher/academic license for [your organization's EDR solution/a popular EDR solution] and build a custom tailored threat hunting lab\u003c/ul\u003e\u003c/ul\u003e\u003c/ul\u003e\u003c/li\u003e\n \u003cul\u003e\u003cul\u003e\u003cli\u003eFor organizations that do not use Sysmon/Windows Events, how can I build threat hunting experience?\u003c/ul\u003e\u003c/ul\u003e\u003c/li\u003e\n \u003cul\u003e\u003cul\u003e\u003cli\u003eETC\u003c/ul\u003c/ul\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003c/p\u003e\n\u003cp\u003e\u003ch1 align=\"center\"\u003e🎤\u003cb\u003ePRACTICE\u003c/b\u003e\u003c/h1\u003e\u003c/p\u003e\n\u003cp\u003e\u003c/p\u003e\n\u003ch3 align=\"left\"\u003e🎵\u003cb\u003eGOAL = PREPARATION\u003c/b\u003e\u003c/h3\u003e\n\n**TRAININGS / HANDS-ON**|**GIVE A TALK**|**HUNT HYPOTHESIS DEV**|**WORK PROJECTS**\n---|---|---|---\nBoss of the SOC (BOTS) - \u003ca href=\"https://live.splunk.com/splunk-security-dataset-project\"\u003eBOTS v1\u003c/a\u003e, \u003ca href=\"https://events.splunk.com/BOTS_2_0_datasets\"\u003eBOTS v2\u003c/a\u003e, \u003ca href=\"https://www.splunk.com/en_us/blog/security/botsv3-dataset-released.html\"\u003eBOTS v3\u003c/a\u003e, ATTACK Range - \u003ca href=\"https://github.com/splunk/attack_range\"\u003eLink\u003c/a\u003e, SPLUNK, \u003ca href=\"https://conf.splunk.com/\"\u003e.conf\u003c/a\u003e Talks, SPLUNK \u003ca href=\"https://www.splunk.com/en_us/about-us/events.html\"\u003eWorkshops\u003c/a\u003e|Talk about something HUNT adjacent|Read Threat Reports \u0026 Think about how YOU would HUNT it, Understand the Technical Attack Chain|Volunteer to work SOC tickets, Volunteer to prep CTI reports for HUNT/PURPLE\n\u003cp\u003e\u003c/p\u003e\n\u003ch3 align=\"left\"\u003e⚔️\u003cb\u003eCH33R10'S HUNT HYPOTHESIS DEV\u003c/b\u003e\u003c/h3\u003e\n\u003col\u003e\n \u003cli\u003e\u003cb\u003eWHAT WOULD THIS BADNESS LOOK LIKE?\u003c/b\u003e\u003c/li\u003e\n \u003cli\u003e\u003cb\u003eWHERE WOULD I FIND IT?\u003c/b\u003e\u003c/li\u003e\n \u003cli\u003e\u003cb\u003eHOW DO I DO THE NEEDFUL?\u003c/b\u003e (What's that search gonna look like?)\u003c/li\u003e\u003c/ol\u003e\n\u003cp\u003e\u003c/p\u003e\n\u003cp\u003e\u003ch1 align=\"center\"\u003e📻\u003cb\u003eAPPLY\u003c/b\u003e\u003c/h1\u003e\u003c/p\u003e\n\u003ch3 align=\"left\"\u003e🎹\u003cb\u003eGOAL = APPLICATION\u003c/b\u003e\u003c/h3\u003e\n\n**MITRE ATT\u0026CK TECHNIQUES**|**CISA / PUBLIC THREAT REPORTS**|**INFOSEC CURRENT EVENTS**\n---|---|---\nPick a few and be able to explain them in DETAIL - \u003ca href=\"https://attack.mitre.org/\"\u003eMITRE ATT\u0026CK\u003c/a\u003e|Develop Hunt Hypotheses with a minimum of 1 hour of content to discuss|Develop hunt scenarios \u0026 understand the technical attack chain\n\u003cp\u003e\u003c/p\u003e\n\u003cp\u003e\u003c/p\u003e\n\u003ch3 align=\"left\"\u003e🔗\u003cb\u003eCH33R10'S THREAT HUNTING CYCLE\u003c/b\u003e\u003c/h3\u003e\n\u003col\u003e\n  \u003cli\u003e\u003cb\u003eRESEARCH\u003c/b\u003e - Hypothesis generation and understanding the technical details.\u003c/li\u003e\n  \u003cli\u003e\u003cb\u003eANALYSIS\u003c/b\u003e - Collect the necessary data, create searches, run the searches, and analyze the results.\u003c/li\u003e\n \u003cli\u003e\u003cb\u003eCONCLUSIONS\u003c/b\u003e - Findings, mitigations, documentation, lessons learned.\u003c/li\u003e\n  \u003cli\u003e\u003cb\u003eDETECTIONS\u003c/b\u003e - Automate the Hunts you can.\u003c/li\u003e\n  \u003cli\u003e\u003cb\u003eRINSE \u0026 REPEAT\u003c/b\u003e\u003c/li\u003e\n\u003c/ol\u003e\n \u003cp\u003e\u003c/p\u003e\n \u003ch3 align=\"left\"\u003e🗡️\u003cb\u003eCH33R10'S THREAT HUNTING TIPS\u003c/b\u003e\u003c/h3\u003e\n \u003col\u003e\n \u003cli\u003e\u003cb\u003eTHREAT HUNT TYPE\u003c/b\u003e\n  \u003cul\u003e\u003cli\u003e\u003cb\u003eSTRUCTURED:\u003c/b\u003e Known TTPs, IOCs, Artifacts\u003c/ul\u003e\u003c/li\u003e\n \u003cul\u003e\u003cli\u003e\u003cb\u003eUNSTRUCTURED:\u003c/b\u003e Unknown\u003c/ul\u003e\u003c/li\u003e\n \u003cli\u003e\u003cb\u003eINTERNAL vs. EXTERNAL\u003c/b\u003e\n \u003cul\u003e\u003cli\u003eExample: Cobalt Strike Beacon Hunting in Network vs. ITW (In the Wild)\u003c/ul\u003e\u003c/li\u003e\n \u003cp\u003e\u003c/p\u003e\n\u003cp\u003e\u003ch1 align=\"center\"\u003e📚\u003cb\u003eLEARNING RESOURCES\u003c/b\u003e\u003c/h1\u003e\u003c/p\u003e\n\u003cp\u003e😎\u003cb\u003eCHEATSHEETS\u003c/b\u003e\u003c/p\u003e\n  \u003cul\u003e\n \u003cli\u003eMalware Archaeology Cheatsheets - Windows - \u003ca href=\"https://www.malwarearchaeology.com/cheat-sheets\"\u003eLink 1\u003c/a\u003e, \u003ca href=\"https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/5d5588b51fd81f0001471db4/1565886646582/Windows+Sysmon+Logging+Cheat+Sheet_Aug_2019.pdf\"\u003eLink 2\u003c/a\u003e, Back up copy for Link 2 - \u003ca href=\"https://github.com/ch33r10/BlueSpace2021/blob/main/rock/Windows%2BSysmon%2BLogging%2BCheat%2BSheet_Aug_2019.pdf\"\u003eLink 3\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eOlaf Hartong. Sysmon Cheatsheet - \u003ca href=\"https://github.com/olafhartong/sysmon-cheatsheet/blob/master/Sysmon-Cheatsheet-dark.pdf\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eSANS Hunt Evil Poster - \u003ca href=\"https://www.sans.org/posters/hunt-evil/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n  \u003cli\u003eSANS Intrusion Discovery for Windows Cheatsheet - \u003ca href=\"https://www.sans.org/posters/intrusion-discovery-cheat-sheet-for-windows/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n  \u003c/ul\u003e\n  \u003cp\u003e\u003c/p\u003e\n\u003cp\u003e🌎\u003cb\u003eDETECTIONS/HUNTS\u003c/b\u003e\u003c/p\u003e\n  \u003cul\u003e\n  \u003cli\u003eBlueTeamLabs - Azure Sentinel Hunting Resource - \u003ca href=\"https://github.com/BlueTeamLabs/sentinel-attack/tree/master/detections\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eDavid J. Bianco. Threat Hunting Project - Threat Hunts - \u003ca href=\"https://github.com/ThreatHuntingProject/ThreatHunting/tree/master/hunts\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n  \u003cli\u003eDetection Ideas Repo by Vadim Khrykov @BlackMatter23 - \u003ca href=\"https://github.com/vadim-hunter/Detection-Ideas-Rules/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eHurricane Labs - Threat Hunting with Splunk: Part 2, Process Creation Log Analysis - \u003ca href=\"https://hurricanelabs.com/splunk-tutorials/threat-hunting-with-splunk-part-2-process-creation-log-analysis/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eRoberto Rodriquez. ThreatHunter Playbook - \u003ca href=\"https://github.com/OTRF/ThreatHunter-Playbook\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eSigma Rules - \u003ca href=\"https://github.com/SigmaHQ/sigma\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eSplunk - Advanced Threat Detection and Response - \u003ca href=\"https://www.splunk.com/pdfs/technical-briefs/advanced-threat-detection-and-response-tech-brief.pdf\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eYARA Rules Resource - \u003ca href=\"https://github.com/InQuest/awesome-yara\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n  \u003c/ul\u003e\n  \u003cp\u003e\u003c/p\u003e\n\u003cp\u003e🏹\u003cb\u003eGENERAL INFO\u003c/b\u003e\u003c/p\u003e\n\u003cul\u003e\n \u003cli\u003eBLOG: BC Security Offensive Security Tools - \u003ca href=\"https://www.bc-security.org/post/category/offensive-security-tools/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eBLOG: Red Canary - \u003ca href=\"https://redcanary.com/blog/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eBLOG: SCYTHE Threat Thursday - \u003ca href=\"https://www.scythe.io/library/threat-thursday-evading-defenses-with-iso-files-like-nobelium\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eBLOG: SpecterOps - \u003ca href=\"https://posts.specterops.io/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eCh33r10's PURPLE TEAM EXERCISE IDEA QUEUE W/ THREAT HUNTING SUGGESTIONS - \u003ca href=\"https://docs.google.com/spreadsheets/d/1wHRrqwb1chTWP8kQqJjA2Chl7bUtCxRlobiyT3V2thE/edit?usp=sharing\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eCh33r10's Twitter Threat Hunting List - \u003ca href=\"https://twitter.com/i/lists/1445402146434867206\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eC2 Matrix by Jorge Orchilles, Bryson Bort \u0026 Adam Mashinchi - \u003ca href=\"https://www.thec2matrix.com/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eC2 Matrix Slingshot VM with C2s Pre-Installed + VECTR by SANS Institute - \u003ca href=\"https://www.sans.org/tools/slingshot/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n\u003cul\u003e\u003cli\u003eDEMO: C2 Matrix VM Walkthru with Jorge Orchilles - \u003ca href=\"https://howto.thec2matrix.com/slingshot-c2-matrix-edition\"\u003eLink\u003c/a\u003e\u003c/ul\u003e\u003c/li\u003e\n \u003cli\u003eDavid J. Bianco and Cat Self. SANS Threat Hunting \u0026 IR Europe Summit 2020 - \u003ca href=\"https://youtu.be/HInxsRyYCK4\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eDavid J. Bianco. Sqrrl Archive - \u003ca href=\"https://www.threathunting.net/sqrrl-archive\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eDavid J. Bianco. The Pyramid of Pain - \u003ca href=\"http://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html\u003eLink\u003c/a\u003e\u003c/li\u003e\n  \u003cli\u003eDavid J. Bianco. The ThreatHunting Project - \u003ca href=\"https://www.threathunting.net/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eDavid J. Bianco. The Threat Hunt Project - Analysis Environment - \u003ca href=\"https://hub.docker.com/r/threathuntproj/hunting/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eDavid J. Bianco. The ThreatHunting Project - Recommended Reading List - \u003ca href=\"https://www.threathunting.net/reading-list\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n  \u003cli\u003eDigit Oktavianto. Cyber Threat Hunting Workshop - \u003ca href=\"https://www.itu.int/en/ITU-D/Cybersecurity/Documents/CyberDrill-2020/Cyber%20Threat%20Hunting%20Workshop%20-%20ITU%2019112020.pdf\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eiRed Team - \u003ca href=\"https://www.ired.team/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eJason Wood. Becoming a Threat Hunter: This Is One Way - Texas Cyber Summit 2021 - \u003ca href=\"https://youtu.be/na1PBrWvJjY\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eJennifer Gruener. DIY Splunk - \u003ca href=\"https://drive.google.com/file/d/1A41Jkydl1z2ydD6ApDjN-fMAYMMNHsHb/view\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eJoshua Stevens. Hunting for the Undefined Threat: Advanced Analytics \u0026 Visualization. RSA Conference 2015 - \u003ca href=\"https://docs.huihoo.com/rsaconference/usa-2015/anf-w04-hunting-the-undefined-threat-advanced-analytics-visualization.pdf\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eMatt Bromiley. Thinking like a Hunter: Implementing a Threat Hunting Program. SANS Analyst Paper - \u003ca href=\"https://www.sans.org/reading-room/whitepapers/analyst/thinking-hunter-implementing-threat-hunting-program-38923\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eMITRE ENGENUITY - ATT\u0026CK Evaluations - \u003ca href=\"https://attackevals.mitre-engenuity.org/\"\u003eLink\u003c/a\u003e\u003c/li\u003e \n \u003cli\u003eRobert M. Lee and David J. Bianco. Generating Hypotheses for Successful Threat Hunting. SANS Analyst White Paper - \u003ca href=\"https://www.sans.org/reading-room/whitepapers/threats/generating-hypotheses-successful-threat-hunting-37172\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n  \u003cli\u003eRoberto Rodriguez. How Hot is your Hunt Team? - \u003ca href=\"https://cyberwardog.blogspot.com/2017/07/how-hot-is-your-hunt-team.html\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eSplunk - Threat Hunting with Splunk: The Basics - \u003ca href=\"https://www.splunk.com/en_us/blog/security/hunting-with-splunk-the-basics.html\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eSqrrl. A Framework for Cyber Threat Hunting - \u003ca href=\"https://www.threathunting.net/files/framework-for-threat-hunting-whitepaper.pdf\"\u003eLink 1\u003c/a\u003e \u0026 Backup copy for Link 1 \u003ca href=\"https://github.com/ch33r10/BlueSpace2021/blob/main/rock/framework-for-threat-hunting-whitepaper.pdf\"\u003eLink 2\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eThe DFIR Report - \u003ca href=\"https://thedfirreport.com/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n  \u003cli\u003eValentina Costa-Gazcon. Practical Threat Intelligence and Data-Driven Threat Hunting - \u003ca href=\"https://www.amazon.com/Practical-Threat-Hunting/dp/1838556370\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n  \u003c/ul\u003e\n  \u003cp\u003e\u003c/p\u003e\n \u003cp\u003e🤓\u003cb\u003eINTERVIEW RESOURCES\u003c/p\u003e\u003c/b\u003e\n \u003cul\u003e\n \u003cli\u003eQuestions for Infosec Job Twitter Thread - \u003ca href=\"https://twitter.com/Ch33r10/status/947868048676945922?s=20\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eQuestions to Find RED FLAGS at a Company Twitter Thread - \u003ca href=\"https://twitter.com/ccieby30/status/1316040342454534144?s=20\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eQuestions to Prepare for Trait-based Interview Questions Twitter Thread - \u003ca href=\"https://twitter.com/jhencinski/status/1450252053188599814?s=20\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003c/ul\u003e\n \u003cp\u003e\u003c/p\u003e\n\u003cp\"\u003e🎺\u003cb\u003eSANS THREAT HUNTING\u003c/b\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eSANS THREAT HUNTING PLAYLIST🎬 - \u003ca href=\"https://youtube.com/playlist?list=PLfouvuAjspTpDHZ4gudmK55ZGDS_NmiDl\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eSANS THREAT HUNTING SUMMIT 2021 Links from the chats collected by Cassie @DFIRDetective - \u003ca href=\"https://start.me/p/DP6oRw/sans-threat-hunting-2021\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSANS THREAT HUNTING SUMMIT 2020🍿 - \u003ca href=\"https://youtube.com/playlist?list=PLfouvuAjspTpESwgitHe8roa7XBOnemFa\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSANS THREAT HUNTING \u0026 INCIDENT RESPONSE SUMMIT 2019📽️ - \u003ca href=\"https://youtube.com/playlist?list=PLfouvuAjspToqZfYaOuWlnHCZUcBTRjzq\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSANS THREAT HUNTING \u0026 INCIDENT RESPONSE SUMMIT 2018🍫 - \u003ca href=\"https://youtube.com/playlist?list=PLfouvuAjspTrUOTh_FTljg3qAXHPtOrIx\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSANS THREAT HUNTING \u0026 INCIDENT RESPONSE SUMMIT 2017🍬 - \u003ca href=\"https://youtube.com/playlist?list=PLfouvuAjspTr95R60Kt7ZcoerR6tYoCLA\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003c/ul\u003e\n  \u003cp\u003e\u003c/p\u003e\n\u003cb\u003e\u003c/b\u003e\n\u003cp\u003e\u003ch1 align=\"center\"\u003e🏋️\u003cb\u003eTRAINING\u003c/b\u003e\u003c/h1\u003e\u003c/p\u003e\n\u003cul\u003e\n  \u003cli\u003eActive Countermeasures - Cyber Threat Hunting Training - Cost: FREE - \u003ca href=\"https://www.activecountermeasures.com/cyber-threat-hunting-training-course/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eApplied Network Defense - Practical Threat Hunting - Cost: 💲 - \u003ca href=\"https://www.networkdefense.co/courses/hunting/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eBlueTeamLabsOnline - Cost: 💲 - \u003ca href=\"https://blueteamlabs.online/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eCyberDefenders - Windows Threat Hunting and others - Cost: FREE \u0026 💲 - \u003ca href=\"https://cyberdefenders.org/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n \u003cli\u003eDetection Lab by Chris Long - Cost: FREE - \u003ca href=\"https://github.com/clong/DetectionLab\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n  \u003cli\u003eINE elearnsecurity - Threat Hunting - Cost: 💲 - \u003ca href=\"https://ine.com\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n  \u003cli\u003eMosse Institute - Certified Threat Hunter - Cost: 💲 - \u003ca href=\"https://www.mosse-institute.com/certifications/mth-certified-threat-hunter.html\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n  \u003cli\u003eSANS FOR508 Advanced Incident Response, Threat Hunting, and Digital Forensics - Cost: 💲 - \u003ca href=\"https://www.sans.org/cyber-security-courses/advanced-incident-response-threat-hunting-training/\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n  \u003cli\u003eSplunk Attack Range - Cost: FREE - \u003ca href=\"https://github.com/splunk/attack_range\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n  \u003cli\u003eSplunk's Boss of the SOC (BOTS) - Cost: FREE - \u003ca href=\"https://live.splunk.com/splunk-security-dataset-project\"\u003eBOTS v1\u003c/a\u003e, \u003ca href=\"https://events.splunk.com/BOTS_2_0_datasets\"\u003eBOTS v2\u003c/a\u003e, \u003ca href=\"https://www.splunk.com/en_us/blog/security/botsv3-dataset-released.html\"\u003eBOTS v3\u003c/a\u003e\u003c/li\u003e\n  \u003cli\u003eSplunk Workshops - Cost: FREE - \u003ca href=\"https://www.splunk.com/en_us/about-us/events.html\"\u003eLink\u003c/a\u003e\u003c/li\u003e\n\u003cb\u003e\u003c/b\u003e\n\u003cp\u003e\u003ch1 align=\"center\"\u003e💎\u003cb\u003eTHANK YOU\u003c/b\u003e\u003c/h1\u003e\u003c/p\u003e\n\u003cul\u003e\n \u003cp\u003eThank you to BlueSpace and Ekoparty! \u003c3\u003c/p\u003e\n \u003cp\u003eShoutout to @plugxor Muchas Gracias!\u003c/p\u003e\n \n\u003c/ul\u003e \n\u003cb\u003e\u003c/b\u003e\n\u003chr\u003e\u003c/hr\u003e\n\u003ch6 align=\"center\"\u003e\u003csmall\u003eFOR THE LAWYERS\u003c/small\u003e\u003c/h6\u003e\n\u003ch6 align=\"center\"\u003e\u003csub\u003e\"The opinions expressed in this Github repo are those of the individual account, in their individual capacity, and not necessarily those of the employers. Mention of any vendors, services, products, or otherwise does not endorse them as a vendor. This content and any related discussions are solely the views, opinions, and experiences of the participants and should not be presumed to reflect the opinion or the official position of any employers of the participants. Examples and views provided herein, including strategies, goals, targets, and indicators are for illustrative purposes only and should not be regarded as representative of the participants' employers or respective portfolios. To the extent that this participation, discussion, and interview outlines a general technology direction, the participants' employers have no obligation to pursue any such approach or to develop or use any functionality mentioned herein. Any suggested technology strategy or possible future developments are subject to change at the employers' sole discretion without notice. Content in this presentation is the intellectual property of the applicable creators and may be protected under the copyright laws of the United States and/or other countries. All trademarks are the property of their respective owners and are used for informational purposes only.\"\u003c/sub\u003e\u003c/h6\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fch33r10%2FBlueSpace2021","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fch33r10%2FBlueSpace2021","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fch33r10%2FBlueSpace2021/lists"}