MalwareLab<p>Collection of one-liners, small scripts and quick howto's for <a href="https://infosec.exchange/tags/blueteam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>blueteam</span></a> by Purp1eW0lf. <br><a href="https://github.com/Purp1eW0lf/Blue-Team-Notes" rel="nofollow noopener" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/Purp1eW0lf/Blue-Tea</span><span class="invisible">m-Notes</span></a></p><p>OS-specific commands for <a href="https://infosec.exchange/tags/windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>windows</span></a> and <a href="https://infosec.exchange/tags/linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>linux</span></a>, network traffic, <a href="https://infosec.exchange/tags/SOC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SOC</span></a>, <a href="https://infosec.exchange/tags/DFIR" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DFIR</span></a>, basic <a href="https://infosec.exchange/tags/malwareanalysis" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>malwareanalysis</span></a>, etc.</p><p>For many years, I have always been equipped with similar manuals in my <a href="https://infosec.exchange/tags/IncidentResponse" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IncidentResponse</span></a> bag such as <a href="https://infosec.exchange/tags/RTFM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RTFM</span></a>: <a href="https://infosec.exchange/tags/RedTeam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RedTeam</span></a> Field Manual and <a href="https://infosec.exchange/tags/SANS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SANS</span></a> Posters and <a href="https://infosec.exchange/tags/cheatsheets" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cheatsheets</span></a>. Either in print or electronic form. I think that the above mentioned Blue-Team Notes will be a nice addition to the incident response collection 🙂</p>