
EventLogging
Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.

Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.


Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)


Dockerized honeypot for CVE-2021-44228.

Indicator of Compromise Scanner for CVE-2019-19781

This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.

Quick One Line Powershell scripts to detect for webshells, possible zips, and logs.

SECMON is a web-based tool for the automation of infosec watching and vulnerability management with a web interface.

Audix is a PowerShell tool to quickly configure the Windows Event Audit Policies for security monitoring

Graph platform for Detection and Response

LDAP Watchdog: A real-time linux-compatible LDAP monitoring tool for detecting directory changes, providing visibility into additions, modifications,…