
loki
Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Provides rapid triage and summarization of malware samples and threat indicators, highlighting key behavioral and contextual details for analysts.

SOC operations content for Microsoft Sentinel, including hunting queries, incident response playbooks, and security event analysis for Azure cloud…

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

A powerful and user-friendly browser extension that streamlines investigations for security professionals.

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Detection-as-code platform that automates cloud security incident response by correlating artifacts, analyzing IOCs, and orchestrating…

A command line tool for pstree-like output on macOS with additional pid capturing capabilities

Botnet command & control monitor

CVE-2020-0618 Honeypot

A GitHub recon/monitoring tool for finding internal leaks belonging to your organisation.

An advanced memory forensics framework

Aggregate, filter, and track CVEs from multiple sources with team collaboration, custom dashboards, alerts, and AI-powered analysis for vulnerability…

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

💻🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.

This module fixes an issue in the kernels filesystem layer (CVE-2021-33909) by kprobe-replacing vulnerable functions during runtime