
loki
Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Find, verify, and analyze leaked credentials

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Provides rapid triage and summarization of malware samples and threat indicators, highlighting key behavioral and contextual details for analysts.

SOC operations content for Microsoft Sentinel, including hunting queries, incident response playbooks, and security event analysis for Azure cloud…

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

A powerful and user-friendly browser extension that streamlines investigations for security professionals.

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Incident Response & Digital Forensics Debugging Extension


A command line tool for pstree-like output on macOS with additional pid capturing capabilities

Detection-as-code platform that automates cloud security incident response by correlating artifacts, analyzing IOCs, and orchestrating…

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Botnet command & control monitor

An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what…

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.