
Sealighter
ETW and WPP tracing tool for security research. Subscribes to multiple providers, auto-parses events to JSON, and supports advanced filtering,…
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

ETW and WPP tracing tool for security research. Subscribes to multiple providers, auto-parses events to JSON, and supports advanced filtering,…

Event Trace Log file parser in pure Python



Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS


This is a repo for fetching Applocker event log by parsing the win-event log

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

Parses Windows .evtx logs to identify remote connections and public IPs by analyzing EventIDs related to remote logins and sessions.

Automated threat hunting and incident response tool for Windows Event Logs with Sigma rule integration, real-time detection, and forensic artifact…

Downloads and aggregates CVSS, EPSS, and CISA known exploited vulnerability data into unified JSON/CSV files and a SQLite database. Enriches…

Automated IP ban service that detects failed login attempts from event logs and files, blocking attackers on Windows and Linux via firewall…

Bash tool used for proactive detection of malicious activity on macOS systems.

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

Community-driven project for documenting, standardizing, and modeling security event logs to improve detection analytics and data normalization…

Incident Response collection and processing scripts with automated reporting scripts

Scans SSL/TLS certificates for expiry dates, issuer details, and OCSP status. Sends notifications via webhook, Telegram, or Slack. Supports proxy per…

Passive DNS Capture and Monitoring Toolkit