
Tylium
Primary data pipelines for intrusion detection, security analytics and threat hunting
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Primary data pipelines for intrusion detection, security analytics and threat hunting

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Hubble is a modular, open-source security compliance framework. The project provides on-demand profile-based auditing, real-time security event…

Daemon to ban hosts that cause multiple authentication errors

Automate the creation of a lab environment complete with security tooling and logging best practices

Next-Gen GUI-based WiFi and Bluetooth Analyzer for Linux

create cypher create statements for neo4j out of netstat files from multiple machines

Security event correlation engine for ELK stack

A Fast (and safe) parser for the Windows XML Event Log (EVTX) format

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through your browser.

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

Data from a BRAWL Automated Adversary Emulation Exercise

Searches For Threat Hunting and Security Analytics

SkyWrapper helps to discover suspicious creation forms and uses of temporary tokens in AWS

A tool to assess data quality, built on top of the awesome OSSEM.

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support