#1IR playbooks, triage, case management, evidence collection, and incident management tools.
Kitploit recommended

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK…

Best Practice Auditd Configuration

Android Logs Events And Protobuf Parser

Python Decoders for Common Remote Access Trojans

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

Advanced macOS system monitor leveraging Apple Endpoint Security to collect, enrich, and display process, file, memory, and XPC events for malware…

Real-time, container-based file scanning at enterprise scale

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Open source templates you can use to bootstrap your security programs

Open-source security framework for real-time event tracking, threat detection, and risk scoring. Monitors user behavior, detects fraud, bot attacks,…

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

ThePhish: an automated phishing email analysis tool

An app that helps you monitor your Kubernetes cluster, debug critical deployments & gives recommendations for standard practices

Security Governance for Agentic AI

Multi-engine Linux malware scanner with five detection stages (MD5, HEX pattern, YARA, ClamAV, statistical), real-time inotify monitoring,…