
bulwark
An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Multi-threaded Windows event log forensics timeline generator and threat hunting tool with full Sigma rule support, producing CSV/JSON timelines for…

A Linux version of the ProcDump Sysinternals tool

OS X Auditor is a free Mac OS X computer forensics tool

PowerShell-based threat hunting tool that analyzes Windows Event Logs to detect malicious activity including credential attacks, obfuscated commands,…

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

ThePhish: an automated phishing email analysis tool

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of…

Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.

The multi-platform memory acquisition tool.

"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events.…