EDR Use Case Library
Detection use cases for CrowdStrike, SentinelOne, and Microsoft Defender. MITRE mapped with FP guidance.
Browse use cases →MITRE to EDR Rule Mapper
Select any MITRE ATT&CK technique and see the exact detection query for each EDR platform.
Map techniques →Sysmon Config Generator
Generate production-ready sysmonconfig.xml with noise level, event types, and exclusions.
Generate config →Threat Hunt Hypothesis Generator
Select an APT group and EDR platform. Get structured hypotheses with ready-to-run queries.
Generate hunt plan →EDR Alert Triage Guide
Step-by-step triage playbooks for Malware, LSASS Access, PowerShell, Lateral Movement alerts.
View triage guide →EDR Maturity Assessment
Score your EDR programme across deployment, detection quality, response capability.
Assess maturity →Process Behaviour Encyclopedia
Normal vs suspicious behaviour for critical Windows processes with red flags.
Browse processes →LOLBin Attack Technique Builder
Every malicious use case for Windows LOLBins with command lines and detection queries.
Browse LOLBins →Windows Event ID Reference
60 most important Windows Security Event IDs with suspicious patterns and MITRE mapping.
Search event IDs →Memory Forensics Reference
Volatility 2 and 3 commands side by side, organised by investigation goal.
View commands →EDR Evasion Reference
How attackers bypass EDR - unhooking, process hollowing, AMSI bypass with detection signals.
View reference →Endpoint Hardening Checklist
Interactive Windows/Linux hardening checklist with CIS benchmark commands.
Start checklist →