
hawk
Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

Basic log analysis tool to detect impossible travel via IP address geographic information

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Client-server tool for live data collection during incident response. Admin sends requests to clients to gather system information for forensic…

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

Artifact collection tool for *nix systems

A GitHub recon/monitoring tool for finding internal leaks belonging to your organisation.

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

LLMNR/NBNS/mDNS Spoofing Detection Toolkit

Simple IP Information Tools for Reputation Data Analysis

Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

Bash tool used for proactive detection of malicious activity on macOS systems.

Incident Response Triage - Windows Evidence Collection for Forensic Analysis