
ThreatLens
Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

A modern and elegant dashboard for network traffic visualization and analysis.

Self-hosted threat intelligence platform — feed aggregation, AI triage, MITRE ATT&CK coverage, and Sentinel-integrated detection engineering. Runs…

create cypher create statements for neo4j out of netstat files from multiple machines

Single-page web dashboard for Meshtastic mesh networks with live network mapping, packet analysis, chat, sensor telemetry, and topology…

Bash tool used for proactive detection of malicious activity on macOS systems.

Parses Snaffler output file and generate beautified outputs.

CVE-2026-85706 — GitLab Path Traversal IOC Scanner & Detection Toolkit. Detect and hunt for exploitation of the critical unauthenticated GitLab CE/EE…

Next-Gen GUI-based WiFi and Bluetooth Analyzer for Linux

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

SECMON is a web-based tool for the automation of infosec watching and vulnerability management with a web interface.

Automated secret and leak detection scanner for GitHub and paste sites, with heuristic filtering, IOL enrichment via Shhgit/TruffleHog, and ELK-based…

Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.

This repository contains a list of new remediation scripts.

Collects and analyzes AD and Azure AD authentication logs to detect lateral movement attacks using graph-based anomaly detection, visualizing…

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.