Vulnerability scanners @GitHub
Tools @Testlab
macOS EDR techniques
Linux EDR techniques
Windows EDR techniques
EDR shell scripts @GitHub
Windows core
Windows sysinternals
Windows event logs
Sysmon
Osquery basics
Runtime container monitoring:
docker exec <container> ps aux sudo sysdig -c spy_users