
matano
Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

SSH-based Linux incident response tool that executes diagnostic commands to collect network configs, logs, user accounts, and processes, then…

Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

ETW and WPP tracing tool for security research. Subscribes to multiple providers, auto-parses events to JSON, and supports advanced filtering,…

Parses Apple Unified Logs to extract process, thread, activity, timestamp, and message metadata from logarchives or live macOS systems into JSONL/CSV…

A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV output from…

PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs

The Sigma command line interface based on pySigma


An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

LDAP Watchdog: A real-time linux-compatible LDAP monitoring tool for detecting directory changes, providing visibility into additions, modifications,…

This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need…

Downloads and aggregates CVSS, EPSS, and CISA known exploited vulnerability data into unified JSON/CSV files and a SQLite database. Enriches…

Indicator of Compromise Scanner for CVE-2019-19781

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Small example repo for looking into log4j CVE-2021-44228