
SuricataLog
Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

RPi3+ Network Cracker Setup Tool

Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research

A tool to monitor local network traffic for possible security vulnerabilities. Warns user against possible nmap scans, Nikto scans, credentials sent…

A simple tool to detect NBT-NS and LLMNR spoofing (and messing with them a bit)

A tool for malicious behavior detection in IoT devices

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

JA4+ is a suite of network fingerprinting standards

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

PacketFence is a fully supported, trusted, Free and Open Source network access control (NAC) solution. Boasting an impressive feature set including a…

Audix is a PowerShell tool to quickly configure the Windows Event Audit Policies for security monitoring

Rust tool to detect cell site simulators on an orbic mobile hotspot

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

A tool to assist with network-based hunting for GRU's Drovorub malware c2

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

Digital forensics and incident response tool using YARA rules to scan Citrix NetScaler core dumps, disk images, and live hosts for signs of…

Deep Learning models for network traffic classification