
MacOSThreatTrack
Bash tool used for proactive detection of malicious activity on macOS systems.

Bash tool used for proactive detection of malicious activity on macOS systems.

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Artifact collection tool for *nix systems

A GitHub recon/monitoring tool for finding internal leaks belonging to your organisation.

Simple IP Information Tools for Reputation Data Analysis

Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

Client-server tool for live data collection during incident response. Admin sends requests to clients to gather system information for forensic…

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

Basic log analysis tool to detect impossible travel via IP address geographic information

A network sniffer that logs all DNS server replies for use in a passive DNS setup

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

A powerful and user-friendly browser extension that streamlines investigations for security professionals.

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

LLMNR/NBNS/mDNS Spoofing Detection Toolkit