014,121 GitHub stars
02Correlation logic for DCOM and remote scheduled task creation
03Multi-vector detection for PtH, PsExec, WMI, RDP, and SMB spreading
04MITRE ATT&CK TA0008 framework mapping and alignment
05Attack path visualization and movement graph generation logic
06Pre-configured Splunk (SPL) queries for Event Logs and Sysmon