Vulnerability scanners @GitHub
Tools @Testlab
macOS EDR techniques
Linux EDR techniques
Windows EDR techniques
EDR shell scripts @GitHub
Windows core
Windows sysinternals
Windows event logs
Sysmon
Osquery basics
Monitor network connections:
sudo lsof -i -P -n | grep ESTABLISHED sudo nettop -P -m route