
sysmon-parser
Automatically generated Sysmon parser for Azure Sentinel

Automatically generated Sysmon parser for Azure Sentinel

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

DEF CON Cloud Village workshop slides teaching KQL for cloud security log analysis, with practical exercises in a shared Azure Log Analytics…

Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…

A security toolkit for Amazon S3

Microsoft Sentinel SIEM Log Source Analyzer

A tool for checking if MFA is enabled on multiple Microsoft Services

Detection signatures for CVE-2026-41940 and shemas for cPanel logs

CI pipeline for building nxlog-ce on Ubuntu with CVE-2020-35488 vulnerability detection, enabling automated log collection and security auditing in…

A Software as a Service (SaaS) log collection framework.

Zero-code K8s sidecar for log sanitization. Detects secrets via Entropy Analysis, preserves JSON integrity, and redacts PII deterministically. 🛡️

Terminal UI for browsing and replaying AWS WAF v2 logs from CloudWatch, S3, and the sampling API, with YAML filtering, auth detection, and…

CVE-2021-38647 - POC to exploit unauthenticated RCE #OMIGOD

Query high-fidelity cloud detections for known threat actors across AWS, Azure, and GCP using CloudTrail logs and custom threat intelligence rules.

Automated cloud security auditing tool that detects AK/SK credential misuse by periodically auditing cloud platform logs using anomaly detection,…

Chronicle parser for CORELIGHT and related information.

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Collection of Google Cloud solution examples and operational utilities for audit log monitoring, DLP de-identification, encryption key management,…