
MrKaplan
PowerShell tool for red teamers that clears execution evidence by stopping event logging, removing file and registry artifacts, and saving timestamps…

PowerShell tool for red teamers that clears execution evidence by stopping event logging, removing file and registry artifacts, and saving timestamps…

Security risk analysis for Kubernetes resources

Tool and framework for securely reading untrusted USB mass storage devices.

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit…

Panic button for protection against cold boot attacks


Runtime application self-protection engine that hooks into application servers to monitor and block malicious database queries, file operations, and…

Runtime Security Enforcement System. Workload hardening/sandboxing and implementing least-permissive policies made easy leveraging LSMs (LSM-BPF,…


A tool to recover from ESXiArgs ransomware

Credential and sensitive-data exposure triage for file shares

Zero-trust sandbox for AI agents with kernel-level filesystem jail, transparent network proxy, and YAML-based policy engine to intercept and control…

Tools and Techniques for Blue Team / Incident Response

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

A unique technique to execute binaries from a password protected zip

An app to protect against process injection and suspicious file links on macOS

OS-level monitor for AI agents: observes processes, file access, and network activity on the local machine and attributes each event to an agent…