
NetScope
Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Single-host runtime-security dashboard on eBPF — Go agent + SvelteKit. Live process tree, network map, and rule-based alerts for plain Linux hosts.

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

OSTE WLA automate the process of analyzing web server logs with the Python Web Log Analyzer.

A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection

A Bro package to identify connections that are bursting (lots of data and transferring quickly).

Enrich the conn.log with EDR data

Open source log management platform for centralized log aggregation, real-time analysis, and security event monitoring with customizable dashboards…

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…