
Agentic-SOC-Simulation
AI 驱动的 SOC 仿真平台
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

AI 驱动的 SOC 仿真平台

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".



A python package for use in generating fake data for SOC and security automation.

Downloads and aggregates CVSS, EPSS, and CISA known exploited vulnerability data into unified JSON/CSV files and a SQLite database. Enriches…

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

Strelka Web UI for File Submission and Analysis

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

A tool to assess data quality, built on top of the awesome OSSEM.

Purpleteam scripts simulation & Detection - trigger events for SOC detections

Artifact collection tool for *nix systems

PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )

Some Threat Hunting queries useful for blue teamers

AI runtime inventory: discover shadow AI, trace LLM calls

DShield Sensor Log Collection with ELK

Sigma rules to share with the community

SkyWrapper helps to discover suspicious creation forms and uses of temporary tokens in AWS