
passivedns
A network sniffer that logs all DNS server replies for use in a passive DNS setup

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Modular incident response toolkit for collecting forensic data from potentially infected macOS endpoints, capturing browser artifacts, persistence…

Spip network sensor written in Go

ThreatSentry AI is an intelligent threat hunting dashboard that leverages machine learning to proactively identify and prioritize risks in your…

Automated, Collection, and Enrichment Platform

LLMNR/NBNS/mDNS Spoofing Detection Toolkit

SQL powered operating system instrumentation, monitoring, and analytics.

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

Cortex: a Powerful Observable Analysis and Active Response Engine

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan,…

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365