
arkime
Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

SQL powered operating system instrumentation, monitoring, and analytics.

A repository of sysmon configuration modules

Detect Tactics, Techniques & Combat Threats

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Galah: An LLM-powered web honeypot.

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Provides curated Sysmon event-tracing configuration templates for detecting Cobalt Strike, webshells, ransomware artifacts, and known exploit…

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…

Collection of private Yara rules.


PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs