Microsoft Defender XDR KQL detections for RedSun, BlueHammer, UnDefend, and CVE-2026-33825-related Defender abuse behaviors.
-
Updated
May 5, 2026
Microsoft Defender XDR KQL detections for RedSun, BlueHammer, UnDefend, and CVE-2026-33825-related Defender abuse behaviors.
A Python desktop application that detects potentially malicious URLs using rule-based phishing analysis with a modern CustomTkinter interface.
Enterprise-grade Security Operations Center (SOC) platform for network traffic analytics, threat detection, incident response, and investigation. Built with Electron, React, FastAPI, Python, and Scapy, featuring asset discovery, packet capture, detection engineering, threat intelligence, and modern SOC workflows.
Add a description, image, and links to the threat-detection-windows topic page so that developers can more easily learn about it.
To associate your repository with the threat-detection-windows topic, visit your repo's landing page and select "manage topics."