
professional-services
Collection of Google Cloud solution examples and operational utilities for audit log monitoring, DLP de-identification, encryption key management,…

Collection of Google Cloud solution examples and operational utilities for audit log monitoring, DLP de-identification, encryption key management,…

Open-source IoT Platform - Device management, data collection, processing and visualization.

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Kratos is a high-performance Windows File System Minifilter driver designed to detect, block, and permanently immunize

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Forensic intelligence platform that analyzes files, correlates threat indicators, maps behavior to MITRE ATT&CK, and generates actionable security…

Java library to analyse Portable Executable files with a special focus on malware analysis and PE malformation robustness

Collection of KQL queries

Zeek package for tracking long connections to report them before they have completed.

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

Fingerprint SSH clients and servers.

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Runs custom filters on Elasticsearch and alerts on matches

Collects and analyzes AD and Azure AD authentication logs to detect lateral movement attacks using graph-based anomaly detection, visualizing…

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

Enumerate various traits from Windows processes as an aid to threat hunting