Skip to content
#

credential-access

Here are 17 public repositories matching this topic...

Unsupervised anomaly detector that flags early breach precursors (credential dumping, process injection) using Isolation Forest on EDR-style process features. Inspired by CrowdStrike-style EDR — includes confidence gating and human-readable explanations—deployed on Streamlit Cloud.

  • Updated Jun 25, 2026
  • Python

Systematic detection engineering on MITRE ATT&CK — the Credential Access tactic decomposed into a full detection suite plus a correlation layer, with range-proving builds in Execution and C2. Microsoft Sentinel · KQL · Defender for Endpoint.

  • Updated Aug 26, 2026
  • HTML

Synthetic SOC / Blue Team credential access detection lab with MITRE ATT&CK mapping, SIEM detection logic, alert triage notes, false-positive handling, detection tuning, and dashboard reporting.

  • Updated Jun 25, 2026

Add this topic to your repo

To associate your repository with the credential-access topic, visit your repo's landing page and select "manage topics."

Learn more