
rip_raw
Rip Raw is a small tool to analyse the memory of compromised Linux systems.
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Audix is a PowerShell tool to quickly configure the Windows Event Audit Policies for security monitoring

Indicator of Compromise Scanner for CVE-2019-19781

Extensible Azure Security Tool - Documentation

Centralize Management of Intrusion Detection System like Suricata Bro Ossec ...


Express security essentials deployment for Linux Servers

This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.

Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.

Quick One Line Powershell scripts to detect for webshells, possible zips, and logs.

Continuously fetches and cryptographically verifies key transparency log updates, maintains a condensed prefix and log tree view, and returns signed…

Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)

Dockerized honeypot for CVE-2021-44228.

Sanitised Windows security lab demonstrating Active Directory administration, host and network detection, and layered mitigation of CVE-2021-34527.

Operational security controls with forensic guarantees