
azureOutlookC2
Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North…

Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North…

Query high-fidelity cloud detections for known threat actors across AWS, Azure, and GCP using CloudTrail logs and custom threat intelligence rules.

Production-grade tool for detecting & remediating CVE-2026-0622 (Ghost Admin privilege escalation & master key exposure in 5G core software).

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

An open source threat modeling tool from OWASP

Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

IMDSPOOF is a cyber deception tool that spoofs the AWS IMDS service to return HoneyTokens that can be alerted on.

Automatically generated Sysmon parser for Azure Sentinel

Robust Subdomain Takeover Tool

Network monitoring tool that maps process-to-network connections, identifies cloud providers, and detects beaconing activity

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

Automated cloud security auditing tool that detects AK/SK credential misuse by periodically auditing cloud platform logs using anomaly detection,…

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

MCP server for structured STRIDE-based threat modeling with automatic code validation, business context analysis, and comprehensive report generation…

Automated threat hunting pipeline that ingests Azure logs, uses LLM reasoning to detect suspicious activity, assess risk, and generate remediation…

🛡️Awesome lists about all kinds of interesting topics of Wazuh XDR/SIEM