
ketshash
A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

Dshell is a network forensic analysis framework.

Build a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit…

SSH bastion/jump host/jumpserver

Investigate malicious Windows logon by visualizing and analyzing Windows event log

The OWASP SecureTea Project provides a one-stop security solution for various devices (personal computers / servers / IoT devices)

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.

OSTE WLA automate the process of analyzing web server logs with the Python Web Log Analyzer.

iOS Debugging Tool 🚀

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs



Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

An Active Defense and EDR software to empower Blue Teams