BEAR-C2 is an adversary simulation and emulation framework built around real-world TTPs inspired by Russian, Chinese, North Korean, and Iranian APT groups.
-
Updated
Aug 26, 2026 - Python
BEAR-C2 is an adversary simulation and emulation framework built around real-world TTPs inspired by Russian, Chinese, North Korean, and Iranian APT groups.
Threat Hunting queries of multiple platforms
Based on Lightspin proprietary data, research, and our tracking of cloud security trends in the market, our research team has compiled a list of the 2022 Top 7 Cloud Attack Paths across AWS, Azure, GCP, and Kubernetes as seen on the Lightspin Cloud Native Application Protection Platform.
Public CTI platform for tracking nation-state APT actors, campaigns, malware, IOCs, and threat activity.
A Tool for Semantic Ranking for Automated Adversarial Technique Annotation in Security Text
A Python script to generate MITRE ATT&CK Navigator layers from TTPs
GyoiThon is a growing penetration test tool using Machine Learning.
Organized goldmine of common TTPs for pentesting / CTFs. Includes folder of canvas files for Obsidian.
Ring -1 engine for MitM attacks on CPU registers. Leverages $DR0$-$DR7$ for zero-footprint interception, real-time data sniffing, and active argument tampering via WriteProcessMemory. Facilitates EDR bypass without modifying app code.
Zero-file, LotL command for memory-resident binary execution. Bypasses EDR vectors by leveraging memfd_create and os.execve to pivot from an obfuscated Base85/Bit-Shift one-liner to a fileless process execution masquerading as a kernel thread without disk footprints.
ttpnav is a Python library that simplifies navigating MITRE ATT&CK data, enabling users to effortlessly retrieve comprehensive information about specific techniques with a single query. It provides details on mitigations, detections, procedure examples, groups, and related software/tools, streamlining cybersecurity analysis.
Interactive Editor for creating & annotating enriched Cyber Kill Chains by mapping MITRE ATT&CK, CAPEC, CWE & STIX 2.1 Objects to the Unified Kill Chain framework. Drag-and-drop interface with metadata, confidence scoring, and export capabilities. Track complex kill chains and combine TTPs with atomic IOCs easily.
AWS Security Best Practices Assessment, Auditing, Hardening and Forensics Readiness Tool. It follows guidelines of the CIS Amazon Web Services Foundations Benchmark and additional checks. Official CIS for AWS guide: https://d0.awsstatic.com/whitepapers/compliance/AWS_CIS_Foundations_Benchmark.pdf
This is an open source python based tool to run Red Team style testing aligned with MITRE Attack Framework TTPs.
Curated list of resources related to serverless architectures and the Serverless Framework
Add a description, image, and links to the ttps topic page so that developers can more easily learn about it.
To associate your repository with the ttps topic, visit your repo's landing page and select "manage topics."