
BlueTeam.Lab
Blue Team detection lab created with Terraform and Ansible in Azure.
Tools for blue team, defensive security, and threat protection.

Blue Team detection lab created with Terraform and Ansible in Azure.

Generate Linux executables that simulate adversary behaviors and techniques for testing detection and response coverage. Consumes JSON for easy…

Self-hosted incident response platform with ticket management, automated reaction playbooks, task tracking, and dashboards for streamlining alert…

Uses Sharphound, Bloodhound and Neo4j to produce an actionable list of attack paths for targeted remediation.

Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique

Enterprise-grade honeypot system for detecting internal network breaches, external threats, and producing threat intelligence with 90+ service…

The world's most powerful System Activity Monitor Engine · 一款功能强大的终端行为采集防御开发套件 ~ 旨在帮助EDR、零信任、数据安全、审计管控等终端安全软件可以快速实现产品功能,…


Scan installed EDRs and AVs on Windows

GlobaLeaks is a free and open-source whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.

Web Service write in Python for control and protect your android device remotely.

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

Obfuscate specific windows apis with different apis

Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security…

Identifies the bytes that Microsoft Defender flags on.

This repo contains some Amsi Bypass methods i found on different Blog Posts.

A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies