
ThreatHound
Automated threat hunting and incident response tool for Windows Event Logs with Sigma rule integration, real-time detection, and forensic artifact…

Automated threat hunting and incident response tool for Windows Event Logs with Sigma rule integration, real-time detection, and forensic artifact…

Dshell is a network forensic analysis framework.

Investigate malicious Windows logon by visualizing and analyzing Windows event log

Multi-threaded Windows event log forensics timeline generator and threat hunting tool with full Sigma rule support, producing CSV/JSON timelines for…

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Android Logs Events And Protobuf Parser

Step-by-step SOC analyst walkthrough for investigating and remediating CVE-2024-3400 (PAN-OS command injection). Covers detection, log analysis,…

Audits Windows event log settings against best-practice guidelines and Sigma-rule detectability, with automated configuration for DFIR readiness.

Event Trace Log file parser in pure Python

Live monitoring tool for remote PowerShell sessions using ETW to capture and decode WinRM/PSRP protocol, providing command execution traces and…

Add POST body excerpt to Bro's HTTP log

A repository to share publicly available Velociraptor detection content

iOS Airborne vulnerabilities log artifact extractor from LogArchive CVE-2025-24252

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

Read-only IOC scanner and mitigation toolkit for cPanel & WHM EmailTrack SQL injection (CVE-2026-67401). Performs version fingerprinting, file…

Curated reference for Android forensic artifacts and log paths, with links to CTF writeups, research papers, and mobile device analysis tooling.