
thingsboard
Open-source IoT Platform - Device management, data collection, processing and visualization.

Open-source IoT Platform - Device management, data collection, processing and visualization.

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Kratos is a high-performance Windows File System Minifilter driver designed to detect, block, and permanently immunize

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Forensic intelligence platform that analyzes files, correlates threat indicators, maps behavior to MITRE ATT&CK, and generates actionable security…

Java library to analyse Portable Executable files with a special focus on malware analysis and PE malformation robustness

Curated collection of Microsoft Sentinel KQL queries and tutorials for hunting threats, analyzing Azure AD sign-in logs, detecting anomalies, and…

Zeek package for tracking long connections to report them before they have completed.

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

Fingerprint SSH clients and servers.

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Runs custom filters on Elasticsearch and alerts on matches

Enumerate various traits from Windows processes as an aid to threat hunting