
Winshark
A wireshark plugin to instrument ETW
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

A wireshark plugin to instrument ETW

Restructured and Collaborated SIEM and CVSS Infrastructure. Presented at Blackhat Asia Arsenal 2020.


APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of…


gundog - guided hunting in Microsoft Defender

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

A python package for use in generating fake data for SOC and security automation.


tshark + ELK analytics virtual machine

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

ETW-based Windows process creation logger that enriches events with file hashes, signatures, and parent process details, outputting to Windows…


Deploy a small, intentionally insecure, vulnerable Windows Domain for RDP Honeypot fully automatically.

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365