
cowrie
Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Threat hunting command system for agentic IDEs

Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

A powerful and user-friendly browser extension that streamlines investigations for security professionals.

Bash tool used for proactive detection of malicious activity on macOS systems.

Botnet command & control monitor

A GitHub recon/monitoring tool for finding internal leaks belonging to your organisation.

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

log4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon (CVE-2021-44228)

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

Collects and analyzes AD and Azure AD authentication logs to detect lateral movement attacks using graph-based anomaly detection, visualizing…

A low to medium interaction honeypot.

Ransomware leak site monitoring

This repository contains a list of new remediation scripts.