
awesome-lists
Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

This repository provides a centralized resource for operational cyber defense and offense, compiling Theory, Tools, Operating Procedures, and…

Full-node Bitcoin client that validates transactions and blocks on the peer-to-peer network, with integrated wallet, cryptographic security, and…

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Tool and framework for securely reading untrusted USB mass storage devices.

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

Android Logs Events And Protobuf Parser

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…


A centralized and enhanced memory analysis platform


Hardened Debian-based privacy OS with pre-integrated anonymity stack (Tor, VPN, DNSCrypt), anti-forensic tooling, SOC security center, and standalone…

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

Portable Linux RAM acquisition tool for forensics and incident response, capturing LiME-compatible images with optional compression and remote…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!