
NetScope
Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Curated collection of Microsoft Sentinel KQL queries and tutorials for hunting threats, analyzing Azure AD sign-in logs, detecting anomalies, and…

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Enumerate various traits from Windows processes as an aid to threat hunting

Basic log analysis tool to detect impossible travel via IP address geographic information

Runs custom filters on Elasticsearch and alerts on matches

Fingerprint SSH clients and servers.

Zeek package for tracking long connections to report them before they have completed.

Open-source IoT Platform - Device management, data collection, processing and visualization.

Forensic intelligence platform that analyzes files, correlates threat indicators, maps behavior to MITRE ATT&CK, and generates actionable security…

Kratos is a high-performance Windows File System Minifilter driver designed to detect, block, and permanently immunize

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Java library to analyse Portable Executable files with a special focus on malware analysis and PE malformation robustness

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

A network packet forensics tool for SSH