
BlueTeam.Lab
Blue Team detection lab created with Terraform and Ansible in Azure.
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Blue Team detection lab created with Terraform and Ansible in Azure.

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

Artifact collection tool for *nix systems

This project is a SIEM with SIRP and Threat Intel, all in one.


Multi-threaded Windows event log forensics timeline generator and threat hunting tool with full Sigma rule support, producing CSV/JSON timelines for…

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

Web-based network monitoring system providing real-time bandwidth tracking, server performance metrics, and customizable alerts for proactive network…

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

Database Driven DNS Server with a Web UI

PowerShell module for Office 365 and Azure log collection

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

Medium-interaction SSH/Telnet honeypot built with Cowrie, Loki, Promtail, and Grafana - provisioned on DigitalOcean via Terraform with a GitLab CI…

Finds the detection rules in your SIEM that are running blind

Open-source security framework for real-time event tracking, threat detection, and risk scoring. Monitors user behavior, detects fraud, bot attacks,…

Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…

CLI tools for forensic investigation of Windows artifacts