#1Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.
Kitploit recommended

Create actionable data from your Vulnerability Scans

Distributed & real time digital forensics at the speed of the cloud

Tracking history of USB events on GNU/Linux

Distributed alerting for the masses!

C# wrapper for ETW that serializes kernel and user-mode event data to JSON for threat hunting, malware analysis, and incident response, with Yara…


Graph platform for Detection and Response

Read-only PowerShell module for detecting UNC2452 and other threat actor artifacts in Azure AD, auditing federated domains, service principals,…

Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.

Easy-to-use live forensics toolbox for Linux endpoints

HonSSH is designed to log all SSH communications between a client and server.

CLI tools for forensic investigation of Windows artifacts

SECMON is a web-based tool for the automation of infosec watching and vulnerability management with a web interface.

Linux vulnerability scanner based on Salt Open and Vulners audit API, with Slack notifications and JIRA integration

LDAP Watchdog: A real-time linux-compatible LDAP monitoring tool for detecting directory changes, providing visibility into additions, modifications,…

Pivotable Reverse WhoIs / PDNS Fusion with Registrant Tracking & Alerting plus API for automated queries (JSON/CSV/TXT)