
awesome-soc-analyst
Useful resources for SOC Analyst and SOC Analyst candidates.
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Useful resources for SOC Analyst and SOC Analyst candidates.

A Simple Ransomware Vaccine

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

A Fast (and safe) parser for the Windows XML Event Log (EVTX) format

Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and…

This repository serves as a place for community created Targets and Modules for use with KAPE.

Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228


A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…


Security Governance for Agentic AI

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Network Security Monitoring on Raspberry Pi type devices