
loki
Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

SOC operations content for Microsoft Sentinel, including hunting queries, incident response playbooks, and security event analysis for Azure cloud…

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Collection of Google Cloud solution examples and operational utilities for audit log monitoring, DLP de-identification, encryption key management,…

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Curated collection of Windows EVTX attack samples mapped to MITRE ATT&CK techniques, designed for testing detection scripts, DFIR training, and…

Live monitoring tool for remote PowerShell sessions using ETW to capture and decode WinRM/PSRP protocol, providing command execution traces and…

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

Dshell is a network forensic analysis framework.

Parses Windows .evtx logs to identify remote connections and public IPs by analyzing EventIDs related to remote logins and sessions.

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Detect Tactics, Techniques & Combat Threats