
Cortex
Cortex: a Powerful Observable Analysis and Active Response Engine

Cortex: a Powerful Observable Analysis and Active Response Engine

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Automation and Scaling of Digital Forensics Tools

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan,…

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of…

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

Windows EDR with Gene-based detection engine, real-time artifact collection, Sysmon integration, and REST API for managing endpoints, rules, and…

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.


Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.

PatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…