
drovorub-hunt
A tool to assist with network-based hunting for GRU's Drovorub malware c2

A tool to assist with network-based hunting for GRU's Drovorub malware c2

A tool to monitor local network traffic for possible security vulnerabilities. Warns user against possible nmap scans, Nikto scans, credentials sent…

Audix is a PowerShell tool to quickly configure the Windows Event Audit Policies for security monitoring

Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

A network packet forensics tool for SSH

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Rust tool to detect cell site simulators on an orbic mobile hotspot

Security Tool to detect arp poisoning attacks

Generates efficient IPv4 blocklists from Zeek network flows using multiple prioritization models (new, consistent, random forest) to identify…

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

Digital forensics and incident response tool using YARA rules to scan Citrix NetScaler core dumps, disk images, and live hosts for signs of…

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

PowerShell-based threat hunting tool that analyzes Windows Event Logs to detect malicious activity including credential attacks, obfuscated commands,…

Monitors for DCSYNC and DCSHADOW attacks and create custom Windows Events for these events.