
ciso-assistant-community
GRC platform for risk management, compliance, and audit with 200+ frameworks, automatic control mapping, vulnerability management, and incident…

GRC platform for risk management, compliance, and audit with 200+ frameworks, automatic control mapping, vulnerability management, and incident…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Detect Tactics, Techniques & Combat Threats

You didn't think I'd go and leave the blue team out, right?

This repository documents how deployment of Microsoft Defender for Endpoint on a Windows 11 device, including onboarding via local script, enabling…

ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.

I was presented with a high-severity alert indicating a potential exploit attempt of CVE-2023-22515, a zero-day vulnerability in Atlassian…

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

AI runtime inventory: discover shadow AI, trace LLM calls

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

OS X Auditor is a free Mac OS X computer forensics tool

Security sensor for realtime threat detection and protection

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Crescendo is a swift based, real time event viewer for macOS. It utilizes Apple's Endpoint Security Framework.
