Blue Team & Detection
The other half of the wiki, read on its own: rule-writing craft, memory forensics workflow, and what each telemetry source can and cannot see.
7 techniques
T1055Windows07-14T1057Windows, Linux08-04T1562.001Windows, Linux, macOS08-04T1562.001Windows08-04T1562.006Windows08-04T1622Windows, Linux, macOS08-04T1622Windows, Linux, macOS08-04
Hunting Unbacked Executable Memory
The single highest-yield structural hunt across the whole injection category.
Memory Forensics with Volatility 3
Triage a memory image to find injected code, rogue processes, and hidden artefacts using Volatility 3.
Behavioral Analytics & UEBA
Detect attacker activity by identifying statistical deviations from baseline user and entity behaviour rather than matching known signatures.
Sysmon Deployment & Tuning
Deploy and tune Sysmon to generate high-fidelity process, network, and file events for threat hunting and incident response.
ETW Telemetry & ETW-TI
Understand what Event Tracing for Windows sees, what it misses, and how attackers try to blind it.
Writing Sigma Detection Rules
Author portable, high-signal Sigma rules that translate to any SIEM without rewriting per-platform.
YARA Memory Scanning
Write and deploy YARA rules that hunt for technique artefacts directly in process memory.
no techniques match those filters.