├── .gitignore ├── LICENSE ├── README.md ├── assets └── img │ └── B_Blue-Jupyter-03.png ├── incident-response └── sysmon-logs │ ├── Processes.ipynb │ ├── Sysmon-Stats.ipynb │ ├── examples │ └── HuntingMetasploit.evtx │ └── sysmon.py ├── log-analysis ├── HTTP.ipynb └── samples │ └── access.log ├── malware-analysis ├── .gitignore ├── Malware-Analysis.ipynb ├── MalwareSample.py ├── README.md ├── dropbox │ ├── SampleNegative.txt │ └── SamplePositive.txt └── saved-specimens │ └── .gitkeep ├── poetry.lock ├── pyproject.toml ├── requirements.txt └── utils ├── __init__.py ├── colors.py └── malware.py /.gitignore: -------------------------------------------------------------------------------- 1 | *__pycache__/ 2 | *.ipynb_checkpoints/ 3 | .idea/**.swp 4 | -------------------------------------------------------------------------------- /LICENSE: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/HuskyHacks/blue-jupyter/HEAD/LICENSE -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/HuskyHacks/blue-jupyter/HEAD/README.md -------------------------------------------------------------------------------- /assets/img/B_Blue-Jupyter-03.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/HuskyHacks/blue-jupyter/HEAD/assets/img/B_Blue-Jupyter-03.png -------------------------------------------------------------------------------- /incident-response/sysmon-logs/Processes.ipynb: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/HuskyHacks/blue-jupyter/HEAD/incident-response/sysmon-logs/Processes.ipynb -------------------------------------------------------------------------------- /incident-response/sysmon-logs/Sysmon-Stats.ipynb: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/HuskyHacks/blue-jupyter/HEAD/incident-response/sysmon-logs/Sysmon-Stats.ipynb -------------------------------------------------------------------------------- /incident-response/sysmon-logs/examples/HuntingMetasploit.evtx: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/HuskyHacks/blue-jupyter/HEAD/incident-response/sysmon-logs/examples/HuntingMetasploit.evtx -------------------------------------------------------------------------------- /incident-response/sysmon-logs/sysmon.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/HuskyHacks/blue-jupyter/HEAD/incident-response/sysmon-logs/sysmon.py -------------------------------------------------------------------------------- /log-analysis/HTTP.ipynb: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/HuskyHacks/blue-jupyter/HEAD/log-analysis/HTTP.ipynb -------------------------------------------------------------------------------- /log-analysis/samples/access.log: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/HuskyHacks/blue-jupyter/HEAD/log-analysis/samples/access.log -------------------------------------------------------------------------------- /malware-analysis/.gitignore: -------------------------------------------------------------------------------- 1 | saved-specimens/* 2 | dropbox/* 3 | -------------------------------------------------------------------------------- /malware-analysis/Malware-Analysis.ipynb: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/HuskyHacks/blue-jupyter/HEAD/malware-analysis/Malware-Analysis.ipynb -------------------------------------------------------------------------------- /malware-analysis/MalwareSample.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/HuskyHacks/blue-jupyter/HEAD/malware-analysis/MalwareSample.py -------------------------------------------------------------------------------- /malware-analysis/README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/HuskyHacks/blue-jupyter/HEAD/malware-analysis/README.md -------------------------------------------------------------------------------- /malware-analysis/dropbox/SampleNegative.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/HuskyHacks/blue-jupyter/HEAD/malware-analysis/dropbox/SampleNegative.txt -------------------------------------------------------------------------------- /malware-analysis/dropbox/SamplePositive.txt: -------------------------------------------------------------------------------- 1 | X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H* -------------------------------------------------------------------------------- /malware-analysis/saved-specimens/.gitkeep: -------------------------------------------------------------------------------- 1 | -------------------------------------------------------------------------------- /poetry.lock: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/HuskyHacks/blue-jupyter/HEAD/poetry.lock -------------------------------------------------------------------------------- /pyproject.toml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/HuskyHacks/blue-jupyter/HEAD/pyproject.toml -------------------------------------------------------------------------------- /requirements.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/HuskyHacks/blue-jupyter/HEAD/requirements.txt -------------------------------------------------------------------------------- /utils/__init__.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/HuskyHacks/blue-jupyter/HEAD/utils/__init__.py -------------------------------------------------------------------------------- /utils/colors.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/HuskyHacks/blue-jupyter/HEAD/utils/colors.py -------------------------------------------------------------------------------- /utils/malware.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/HuskyHacks/blue-jupyter/HEAD/utils/malware.py --------------------------------------------------------------------------------