
WhoDat
Pivotable Reverse WhoIs / PDNS Fusion with Registrant Tracking & Alerting plus API for automated queries (JSON/CSV/TXT)
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Apache Real Time Logs Analyzer System

A host-based IDS and network monitoring system (My graduation project)


PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.


gundog - guided hunting in Microsoft Defender

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

A tool to subscribe to receive all standard Android broadcasts on your Android device.

SkyWrapper helps to discover suspicious creation forms and uses of temporary tokens in AWS

CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065

Quick One Line Powershell scripts to detect for webshells, possible zips, and logs.

Bro analyzer that detects Google's QUIC protocol

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

SSH bastion/jump host/jumpserver

MITRE ATT&CK mapped queries for SentinelOne Deep Visiblity
