#1IR playbooks, triage, case management, evidence collection, and incident management tools.
Kitploit recommended

Distributed alerting for the masses!

honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS…

MICROS Honeypot is a low interaction honeypot to detect CVE-2018-2636 in the Oracle Hospitality Simphony component of Oracle Hospitality Applications…

Volatility plugins for memory forensics, including detection of Gargoyle memory scanning evasion techniques.

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Data from a BRAWL Automated Adversary Emulation Exercise

analyze a web-based network traffic 🕶 to detect central command and control servers

Scripts for extracting useful information from infected memory dumps

Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600

Contains tools to perform malware and forensic analysis in Memory

Cmd.exe Command Obfuscation Generator & Detection Test Harness

Monitors for DCSYNC and DCSHADOW attacks and create custom Windows Events for these events.

Automated, Collection, and Enrichment Platform

Build a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI

Issues to consider when planning a red team exercise.

Exploit script for CVE-2017-0290 targeting Windows Defender on Windows 8.1/10, designed to disable or bypass the built-in antivirus protection.

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

Disables Jenkins CLI/Remoting subsystem as a mitigation against unauthenticated remote code execution vulnerabilities SECURITY-218 and SECURITY-360,…