
iocx
An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern…

An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern…

Detection-as-code platform that automates cloud security incident response by correlating artifacts, analyzing IOCs, and orchestrating…

An advanced memory forensics framework

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

PatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform

Regipy is an os independent python library for parsing offline registry hives

CredsHunter - Credential Hunting scripts for Windows and Linux OS

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

Just my findings of malwares

SQL powered operating system instrumentation, monitoring, and analytics.

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

A binary authorization and monitoring system for macOS

Tools and Techniques for Blue Team / Incident Response

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

A repository of sysmon configuration modules