
BLUESPAWN
An Active Defense and EDR software to empower Blue Teams

An Active Defense and EDR software to empower Blue Teams

A repository that maps commonly used attacks using MSRPC protocols to ATT&CK

Recognizing the most likely APT groups responsible for an incident

LLMNR/NBNS/mDNS Spoofing Detection Toolkit

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

Botnet command & control monitor

Open source Android, iOS and Web app for learning about and managing digital and physical security. From how to send a secure message to dealing with…

Enumerate various traits from Windows processes as an aid to threat hunting

End-to-end simulation of detecting a root-less Android Drop Device (Casper) using Wazuh SIEM to capture Layer 7 attacks like Shellshock…

general purpose workaround for the log4j CVE-2021-44228 vulnerability

CVE-2026-48907