
EventHorizon
Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

Modular incident response toolkit for collecting forensic data from potentially infected macOS endpoints, capturing browser artifacts, persistence…

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

Best Practice Auditd Configuration

Incident Response & Digital Forensics Debugging Extension

Blue Team detection lab created with Terraform and Ansible in Azure.

iOS Airborne vulnerabilities log artifact extractor from LogArchive CVE-2025-24252

A repository of sysmon configuration modules

PacketFence is a fully supported, trusted, Free and Open Source network access control (NAC) solution. Boasting an impressive feature set including a…

CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065