
Credential-Hunting
CredsHunter - Credential Hunting scripts for Windows and Linux OS

CredsHunter - Credential Hunting scripts for Windows and Linux OS

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

SQL powered operating system instrumentation, monitoring, and analytics.

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…


Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Cortex: a Powerful Observable Analysis and Active Response Engine

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan,…

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

StalkPhish - The Phishing kits stalker, harvesting phishing kits for investigations.

Operational information regarding CVE-2022-3602 and CVE-2022-3786, two vulnerabilities in OpenSSL 3