Awesome Cybersecurity Blue Team 
A collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.
Cybersecurity blue teams are groups of individuals who identify security flaws in information technology systems, verify the effectiveness of security measures, and monitor the systems to ensure that implemented defensive measures remain effective in the future. While not exclusive, this list is heavily biased towards Free Software projects and against proprietary products or corporate services. For offensive TTPs, please see awesome-pentest.
Your contributions and suggestions are heartily ♥ welcome. (✿◕‿◕). Please check the Contributing Guidelines for more details. This work is licensed under a Creative Commons Attribution 4.0 International License.
Many cybersecurity professionals enable racist state violence, wittingly or unwittingly, by providing services to local, state, and federal policing agencies or otherwise cooperating with similar institutions who do so. This evil most often happens through the coercive mechanism of employment under threat of lack of access to food, shelter, or healthcare. Despite this list's public availability, it is the maintainer's intention and hope that this list supports the people and organizations who work to counter such massive albeit banal evil.


DEFUND THE POLICE.
Contents
Automation and Convention
- Ansible Lockdown - Curated collection of information security themed Ansible roles that are both vetted and actively maintained.
- Clevis - Plugable framework for automated decryption, often used as a Tang client.
- DShell - Extensible network forensic analysis framework written in Python that enables rapid development of plugins to support the dissection of network packet captures.
- Dev-Sec.io - Server hardening framework providing Ansible, Chef, and Puppet implementations of various baseline security configurations.
- Password Manager Resources - Collaborative, crowd-sourced data and code to make password management better.
- peepdf - Scriptable PDF file analyzer.
- PyREBox - Python-scriptable reverse engineering sandbox, based on QEMU.
- Watchtower - Container-based solution for automating Docker container base image updates, providing an unattended upgrade experience.
Code libraries and bindings
- MultiScanner - File analysis framework written in Python that assists in evaluating a set of files by automatically running a suite of tools against them and aggregating the output.
- Posh-VirusTotal - PowerShell interface to VirusTotal.com APIs.
- censys-python - Python wrapper to the Censys REST API.
- libcrafter - High level C++ network packet sniffing and crafting library.
- python-dshield - Pythonic interface to the Internet Storm Center/DShield API.
- python-sandboxapi - Minimal, consistent Python API for building integrations with malware sandboxes.
- python-stix2 - Python APIs for serializing and de-serializing Structured Threat Information eXpression (STIX) JSON content, plus higher-level APIs for common tasks.
Security Orchestration, Automation, and Response (SOAR)
See also Security Information and Event Management (SIEM), and IR management consoles.
- Shuffle - Graphical generalized workflow (automation) builder for IT professionals and blue teamers.
See also asecure.cloud/tools.