
tpotce
🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

SQL powered operating system instrumentation, monitoring, and analytics.

Automate the creation of a lab environment complete with security tooling and logging best practices

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

JA4+ is a suite of network fingerprinting standards

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

A Simple Ransomware Vaccine

Documentation and scripts to properly enable Windows event logs.

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.

A network packet forensics tool for SSH

Blue Team detection lab created with Terraform and Ansible in Azure.

Network anomaly detector that monitors raw packets to identify port scanning activity in real time, with flexible sniffing duration controls and live…

Audix is a PowerShell tool to quickly configure the Windows Event Audit Policies for security monitoring

Conveigh is a Windows PowerShell LLMNR/NBNS spoofer detection tool

Default Detections for EDR

Primary data pipelines for intrusion detection, security analytics and threat hunting

Curated collection of threat hunting and detection queries for CrowdStrike Falcon (CQL) and Microsoft Defender XDR (KQL), mapped to MITRE ATT&CK…