


Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

ioc2rpz is a place where threat intelligence meets DNS.

RPi3+ Network Cracker Setup Tool

Open-source deception platform that turns any Linux machine into a high-signal canary. Deploy tripwire sensors on files, ports, and network services…

A network packet forensics tool for SSH

The Sigma command line interface based on pySigma

TheLightScope

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

Fingerprint SSH clients and servers.


Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)

Runtime application self-protection engine that hooks into application servers to monitor and block malicious database queries, file operations, and…

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

A script to configure a TP-Link MR3040 running OpenWRT into a simple, yet powerful penetration-testing "dropbox".

Converts Sigma detection rules into OpenSearch Lucene and PPL queries, including alerting Monitor Rules and correlation support for SIEM detection…