
mig
Distributed & real time digital forensics at the speed of the cloud
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Tracking history of USB events on GNU/Linux

Distributed alerting for the masses!


Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Graph platform for Detection and Response


Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.

Easy-to-use live forensics toolbox for Linux endpoints

HonSSH is designed to log all SSH communications between a client and server.

CLI tools for forensic investigation of Windows artifacts

SECMON is a web-based tool for the automation of infosec watching and vulnerability management with a web interface.

Linux vulnerability scanner based on Salt Open and Vulners audit API, with Slack notifications and JIRA integration

LDAP Watchdog: A real-time linux-compatible LDAP monitoring tool for detecting directory changes, providing visibility into additions, modifications,…

GitHub mirror of the Linux Kernel's audit repository