
BearFTP
Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

ETW and WPP tracing tool for security research. Subscribes to multiple providers, auto-parses events to JSON, and supports advanced filtering,…

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Tracking history of USB events on GNU/Linux

CVE-2022-31814 Exploitation Toolkit.

Deploy a small, intentionally insecure, vulnerable Windows Domain for RDP Honeypot fully automatically.

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from…

A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further…


This is a repo for fetching Applocker event log by parsing the win-event log

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

ETW-based Windows process creation logger that enriches events with file hashes, signatures, and parent process details, outputting to Windows…