
matano
Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

SQL powered operating system instrumentation, monitoring, and analytics.

Dshell is a network forensic analysis framework.

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

A repository of sysmon configuration modules

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Detect Tactics, Techniques & Combat Threats

Curated collection of Microsoft Sentinel KQL queries and tutorials for hunting threats, analyzing Azure AD sign-in logs, detecting anomalies, and…

APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of…

Tracking history of USB events on GNU/Linux

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Distributed alerting for the masses!

Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and…

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…