
fastnetmon
Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

the TCPdump network dissector

Investigate malicious Windows logon by visualizing and analyzing Windows event log

Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

Multi-threaded Windows event log forensics timeline generator and threat hunting tool with full Sigma rule support, producing CSV/JSON timelines for…

Rapidly Search and Hunt through Windows Forensic Artefacts

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

Dshell is a network forensic analysis framework.

OS X Auditor is a free Mac OS X computer forensics tool

Kyanos is a networking analysis tool using eBPF. It can visualize the time packets spend in the kernel, capture requests/responses, makes…

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation.…


Microsoft Threat Intelligence Security Tools



This project aims to compare and evaluate the telemetry of various EDR products.

Detect Tactics, Techniques & Combat Threats

A list of cyber-chef recipes and curated links