010 GitHub stars
02Behavioral pattern analysis for identifying Living-off-the-Land (LOLBin) abuse and C2 beaconing.
03Dynamic LCQL query construction with automatic Unix epoch timestamp calculation.
04Forensic deep-dives using sensor commands for memory strings, file hashes, and process trees.
05Hypothesis-driven investigation workflows aligned with MITRE ATT&CK tactics.
06Detection engineering to convert manual hunts into automated D&R rules.