
StalkPhish
Open-source tool for harvesting and analyzing phishing kits to support threat intelligence, incident response, and phishing investigations.

Open-source tool for harvesting and analyzing phishing kits to support threat intelligence, incident response, and phishing investigations.

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

A powerful and user-friendly browser extension that streamlines investigations for security professionals.

PowerShell-based guided hunting tool for Microsoft 365 Defender that automates alert triage, entity enrichment, and IOC lookups across email and…

A GitHub recon/monitoring tool for finding internal leaks belonging to your organisation.

Automated ransomware leak site scraper that monitors dark web and clearnet sites for new victims, stores data in SQLite, and sends real-time alerts…

A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

Bash tool used for proactive detection of malicious activity on macOS systems.

Turn Rootly incidents, alerts, and teams into a queryable knowledge graph. Visualize service dependencies, on-call coverage gaps, and cross-incident…

Simple IP Information Tools for Reputation Data Analysis

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

Message-queue-based threat intelligence feed collector and processor for CSIRTs. Automates ingestion, normalization, and sharing of security…

Scans filesystems and archives for Log4j libraries vulnerable to CVE-2021-44228 (Log4Shell) using PowerShell, aiding rapid incident response and…

Passive DNS honeypot that captures unsolicited queries using Unbound, Loki, Prometheus, and Grafana. Logs client IPs, queried domains, and throughput…

Modular botnet command & control monitor with IRC/HTTP protocol support, SOCKS proxy anonymization, XMPP sensor coordination, and RESTful API for…

Remote code execution exploit for Citrix ADC and Gateway (CVE-2019-19781) with vulnerability detection, exploitation scripts, and…

Lightweight low-interaction network honeypot sensor that captures TCP payloads, performs passive TLS/HTTP/SSH fingerprinting, and outputs structured…

Repository documenting CVE-2019-19781 with a scanner, honeypot, and DFIR notes for Citrix ADC vulnerability detection and incident response.