
loki
Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Live monitoring tool for remote PowerShell sessions using ETW to capture and decode WinRM/PSRP protocol, providing command execution traces and…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

The easiest, and most secure way to access and protect all of your infrastructure.

Audix is a PowerShell tool to quickly configure the Windows Event Audit Policies for security monitoring

Extensible Azure Security Tool - Documentation

OS X Auditor is a free Mac OS X computer forensics tool

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

SSH-based Linux incident response tool that executes diagnostic commands to collect network configs, logs, user accounts, and processes, then…

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

A collection of scripts which may come in handy during your freedom fighting activities.

LDAP Watchdog: A real-time linux-compatible LDAP monitoring tool for detecting directory changes, providing visibility into additions, modifications,…

Live kernel signal observability tool using eBPF tracepoints to stream every signal raised on a Linux host, showing sender, target, disposition,…

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

Automatically generated Sysmon parser for Azure Sentinel

Analyzes Nginx access logs to detect SQL injection, scanner tools, webshells, and exploitation attempts, aiding system administrators in server…