
loki
Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

IFRIT is an AI-powered reverse proxy that intercepts incoming requests in real time, classifying each one as legitimate or malicious. Legitimate…

Detection-as-code platform that automates cloud security incident response by correlating artifacts, analyzing IOCs, and orchestrating…

Goal is to triage well known attacks and learn how security teams quickly respond.

Re-play Security Events

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

A GitHub recon/monitoring tool for finding internal leaks belonging to your organisation.

Puppet Module to help fix and migrate a Puppet deployment (CVE-2011-3872)

AI IR Overlay™ — practical incident response framework for AI agents in production. Built on NIST SP 800-61 r3, mapped to NIST AI RMF, NIST CSF 2.0,…

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Selective protocol extractor from PCAPs or interfaces

Tuning and refactoring Google Chronicle Curated Detections to eliminate alert fatigue and fix logic gaps/bugs.

A repository to share publicly available Velociraptor detection content

Open-source platform to secure and manage endpoints via MDM, patch management, software deployment, and osquery-powered visibility with compliance…


Forensic library and CLI toolkit for analyzing disk and file system images, recovering deleted data, generating timelines, and validating evidence…

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact