
nightHawkResponse
Incident Response Forensic Framework
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Incident Response Forensic Framework


DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

🐍 High-performance, multi-threaded YARA & IOC scanner

A curated collection of DFIR skills and workflows for InfoSec practitioners.

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Web-based network monitoring system providing real-time bandwidth tracking, server performance metrics, and customizable alerts for proactive network…

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

A collection of scripts which may come in handy during your freedom fighting activities.

Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…

Provides curated Sysmon event-tracing configuration templates for detecting Cobalt Strike, webshells, ransomware artifacts, and known exploit…

DECeption with Evaluative Integrated Validation Engine (DECEIVE): Let an LLM do all the hard honeypot work!

OWASP Honeypot, Automated Deception Framework.

SSH bastion/jump host/jumpserver


Security event correlation engine for ELK stack

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…