
AlertResponder
Automatic security alert response framework by AWS Serverless Application Model

Automatic security alert response framework by AWS Serverless Application Model

A low to medium interaction honeypot.


An ssh honeypot with the XZ backdoor. CVE-2024-3094

Scan your Windows computer for known vulnerable or malicious drivers.

LLMNR/NBNS/mDNS Spoofing Detection Toolkit

Spip network sensor written in Go

Simple honeypot for CVE-2024-3400 Palo Alto PAN-OS Command Injection Vulnerability

Threat-Informed Detection & Mitigation Package for MOVEit Transfer Vulnerability


Curated collection of Microsoft Sentinel KQL queries and tutorials for hunting threats, analyzing Azure AD sign-in logs, detecting anomalies, and…

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

Scan files or process memory for CobaltStrike beacons and parse their configuration

PowerShell tool for red teamers that clears execution evidence by stopping event logging, removing file and registry artifacts, and saving timestamps…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

A tool that removes traces of executed applications on Windows OS.

Powerglot encodes offensive powershell scripts using polyglots . Offensive security tool useful for stego-malware, privilege escalation, lateral…

Draw.io libraries for threat modeling diagrams