
osquery
SQL powered operating system instrumentation, monitoring, and analytics.

SQL powered operating system instrumentation, monitoring, and analytics.

A Software as a Service (SaaS) log collection framework.

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

Static vulnerability findings tracker with parallel search across 11 CVE databases, EPSS enrichment, CISA KEV badges, coordinated disclosure…


A repository of sysmon configuration modules


Detect Tactics, Techniques & Combat Threats

Spip network sensor written in Go

Kratos is a high-performance Windows File System Minifilter driver designed to detect, block, and permanently immunize

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

This repository contains a list of new remediation scripts.

Tools and Techniques for Blue Team / Incident Response

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…
