
Douglas-042
Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

Read-only post-exploitation credential hunter that surfaces reusable passwords, keys, hashes, and credential files across Windows and Linux hosts…

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

Lightweight low-interaction network honeypot sensor that captures TCP payloads, performs passive TLS/HTTP/SSH fingerprinting, and outputs structured…

Threat hunting command system for agentic IDEs

Automated observable analysis engine for threat intelligence, digital forensics, and incident response, integrating with diverse analyzers via a…

Read-only WordPress User Registration CVE-2026-1492 checker for hidden admins, plugin version, uploads PHP, cron, and compromise IOCs.

Automated vulnerability scanner for CVE-2026-0257 (PAN-OS GlobalProtect Authentication Bypass) with TLS certificate enumeration, authentication…

A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

Passive DNS honeypot that captures unsolicited queries using Unbound, Loki, Prometheus, and Grafana. Logs client IPs, queried domains, and throughput…

Message-queue-based threat intelligence feed collector and processor for CSIRTs. Automates ingestion, normalization, and sharing of security…

Turn Rootly incidents, alerts, and teams into a queryable knowledge graph. Visualize service dependencies, on-call coverage gaps, and cross-incident…

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

ML-powered threat hunting dashboard that automates external asset discovery, enriches data via Shodan and NVD, and prioritizes risks using ensemble…

PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory domain…

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Bash tool used for proactive detection of malicious activity on macOS systems.

A powerful and user-friendly browser extension that streamlines investigations for security professionals.