
loki
Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Open-source platform to secure and manage endpoints via MDM, patch management, software deployment, and osquery-powered visibility with compliance…

Find, verify, and analyze leaked credentials

Goal is to triage well known attacks and learn how security teams quickly respond.

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

OS-level monitor for AI agents: observes processes, file access, and network activity on the local machine and attributes each event to an agent…

Query high-fidelity cloud detections for known threat actors across AWS, Azure, and GCP using CloudTrail logs and custom threat intelligence rules.

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and…

SOC operations content for Microsoft Sentinel, including hunting queries, incident response playbooks, and security event analysis for Azure cloud…

Provides rapid triage and summarization of malware samples and threat indicators, highlighting key behavioral and contextual details for analysts.

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

AI IR Overlay™ — practical incident response framework for AI agents in production. Built on NIST SP 800-61 r3, mapped to NIST AI RMF, NIST CSF 2.0,…