
Incident-Response-Powershell
PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

IFRIT is an AI-powered reverse proxy that intercepts incoming requests in real time, classifying each one as legitimate or malicious. Legitimate…

A complete Blue Team Cybersecurity Lab featuring pfSense, Suricata, and ELK Stack for network monitoring and threat detection.

Self-hosted threat intelligence platform — feed aggregation, AI triage, MITRE ATT&CK coverage, and Sentinel-integrated detection engineering. Runs…

Bash tool used for proactive detection of malicious activity on macOS systems.

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Live kernel signal observability tool using eBPF tracepoints to stream every signal raised on a Linux host, showing sender, target, disposition,…

Lightweight macOS detection agent built on Santa’s Endpoint Security telemetry.

Demonstrates exploitation of CVE-2024-4577, a PHP CGI RCE on Windows, including attack steps, reverse shell deployment, and ransomware simulation…

Apache Real Time Logs Analyzer System

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive…

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

Community-driven project for documenting, standardizing, and modeling security event logs to improve detection analytics and data normalization…

Detect Tactics, Techniques & Combat Threats

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Real-time monitoring and slowlog analysis for Valkey and Redis databases with anomaly detection, ACL auditing, and Prometheus metrics export.