
forensic-msvpn
This repository contains Velociraptor artifact and Chainsaw rules to help detect Microsoft Remote Access VPN activity
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

This repository contains Velociraptor artifact and Chainsaw rules to help detect Microsoft Remote Access VPN activity

Useful resources for SOC Analyst and SOC Analyst candidates.

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

Web-based network monitoring system providing real-time bandwidth tracking, server performance metrics, and customizable alerts for proactive network…

A ProcessMonitor visualization application written in rust.


Zeek support for Community ID flow hashing.

Hubble is a modular, open-source security compliance framework. The project provides on-demand profile-based auditing, real-time security event…

Parses Windows .evtx logs to identify remote connections and public IPs by analyzing EventIDs related to remote logins and sessions.


Community Detection Signature Build and Distribution Pipeline for YARA, Suricata, Snort and Sigma

A Zeek OpenVPN protocol analyzer plugin.

Ruby On Rails Application For Network Security Monitoring


Extensible Azure Security Tool - Documentation

Advanced detection of port scanning, DoS and malware attacks using Machine Learning techniques

Runs custom filters on Elasticsearch and alerts on matches