
ThreatLens
Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

A network sniffer that logs all DNS server replies for use in a passive DNS setup

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

A powerful and user-friendly browser extension that streamlines investigations for security professionals.

Bash tool used for proactive detection of malicious activity on macOS systems.

A GitHub recon/monitoring tool for finding internal leaks belonging to your organisation.

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

Ransomware leak site monitoring

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

Basic log analysis tool to detect impossible travel via IP address geographic information

Artifact collection tool for *nix systems

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

LLMNR/NBNS/mDNS Spoofing Detection Toolkit

Simple IP Information Tools for Reputation Data Analysis

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.