
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.



Some Threat Hunting queries useful for blue teamers

** DISPUTED ** 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the…

Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228

SECMON is a web-based tool for the automation of infosec watching and vulnerability management with a web interface.

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

A wireshark plugin to instrument ETW

Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and…

Primary data pipelines for intrusion detection, security analytics and threat hunting

OpenIOC rules to facilitate hunting for indicators of compromise

HonSSH is designed to log all SSH communications between a client and server.


Repo containing all info, scripts, etc. related to CVE-2021-44228

fail2ban filter that catches attacks againts log4j CVE-2021-44228

CVE-2021-44228

Small example repo for looking into log4j CVE-2021-44228

A Smart Log4Shell/Log4j/CVE-2021-44228 Scanner