
intelmq
IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan,…

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

A powerful and user-friendly browser extension that streamlines investigations for security professionals.

This repository contains a list of new remediation scripts.

Collecting & Hunting for IOCs with gusto and style

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

CredsHunter - Credential Hunting scripts for Windows and Linux OS

Artifact collection tool for *nix systems

Modular incident response toolkit for collecting forensic data from potentially infected macOS endpoints, capturing browser artifacts, persistence…

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

Turn Rootly incidents, alerts, and teams into a queryable knowledge graph. Visualize service dependencies, on-call coverage gaps, and cross-incident…

A portable C# utility for enumerating local and remote windows sessions

Bash tool used for proactive detection of malicious activity on macOS systems.