
Azure-Sentinel
Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Canarytokens helps track activity and actions on your network

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…


Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

An informational repo about hunting for adversaries in your IT environment.

AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK…

Open source templates you can use to bootstrap your security programs

An app that helps you monitor your Kubernetes cluster, debug critical deployments & gives recommendations for standard practices

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

A security auditor for Tailscale configurations. Scans your tailnet for misconfigurations, overly permissive access controls, and security best…

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

Docker configuration to quickly setup your own Canarytokens.

Paperweight scans your inbox to map your digital footprint, then helps you take back control and delete your data. Local-first and open source.

PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs

InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution

Read-only AI agent that queries your cloud, code, and runtime infrastructure to surface misconfigurations, leaked secrets, and privilege escalation…

An ADCS honeypot to catch attackers in your internal network.