
KQL-threat-hunting-queries
A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).

A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).

Advanced Burp Suite Logging Extension


This package extends the Intel package to log more fields

Kyanos is a networking analysis tool using eBPF. It can visualize the time packets spend in the kernel, capture requests/responses, makes…

PEAK Baseline Threat Hunt dashboards for Security Onion 3.0 — covering DNS, HTTP, TLS, SMB, Kerberos, SSH, RDP, DCE/RPC, LDAP, Modbus, DNP3,…

🔐 Secure, real-time monitoring dashboard for OpenClaw AI agents. Auth, TOTP MFA, cost tracking, live feed, memory browser and more.

Microsoft Sentinel SIEM Log Source Analyzer

A tool to assess data quality, built on top of the awesome OSSEM.

A python package for use in generating fake data for SOC and security automation.

tshark + ELK analytics virtual machine

ETW-based Windows process creation logger that enriches events with file hashes, signatures, and parent process details, outputting to Windows…

This project is a SIEM with SIRP and Threat Intel, all in one.