#1IR playbooks, triage, case management, evidence collection, and incident management tools.
Kitploit recommended

A curated knowledge base to build, run and mature a SOC (including CSIRT).
eBPF-based Linux security monitor and threat hunter providing chronologically ordered, container-aware events with on-host correlation for incident…

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

SOC detection rules and content for T1003.001 LSASS credential dumping and CVE-2021-40444 exploitation activity.

SécurixOS is a NixOS-based secure operating system tailored for small to medium-sized teams. It provides a minimal, hardened environment with strong…

Android Logs Events And Protobuf Parser

Read-only defensive detector for CVE-2026-94127 in F5 BIG-IP APM. Fingerprints hosts, checks versions via iControl REST, and verifies OAuth…

Open-source security orchestration, automation, and response (SOAR) platform with a visual workflow editor, prebuilt security app integrations, and…

LetsDefend SOC lab investigating CVE-2024-49138 and related malicious activity.

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

IAM for your AI agents. Set what Claude Code, Codex, Gemini, Cursor and any MCP server are allowed to do, review risky actions before they run, and…

Curated JSON object templates that define MISP attributes and relationship types for structured threat intelligence sharing and interoperable IOC…

Curated IPv4 blocklist of malicious addresses, refreshed every 6 hours for firewall and WAF ingestion, with split lists and CTI-ready formats for…

Detection toolkit and reproducible lab for CVE-2026-87902, an unauthenticated WordPress path traversal. Includes remote checker, IoC analyzer, Sigma…

Spip network sensor written in Go

Shell and SmartDashboard scripts that check Check Point management servers for indicators of compromise tied to CVE-2026-93616, including rogue…

SQL powered operating system instrumentation, monitoring, and analytics.

Microsoft Threat Intelligence Security Tools