
loki
Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Spip network sensor written in Go

You didn't think I'd go and leave the blue team out, right?

PowerShell-based security toolkit for small-to-medium enterprises, providing automated alerts, Active Directory hardening, Windows Event Forwarding,…

Fork of the AT Protocol reference implementation with performance-optimized AppView, Rust-based firehose indexer, Redis caching, and community…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

CQL Hub is an open repository of detection and hunting queries for CrowdStrike NextGen SIEM and Falcon LogScale. All queries stored here are…

Detection-first incident-response toolkit for Zimbra administrators investigating CVE-2026-73570. Searches logs for exploit indicators, examines…

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…

This repository contains a list of new remediation scripts.

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Passive DNS Capture and Monitoring Toolkit

This project aims to compare and evaluate the telemetry of various EDR products.

GitHub mirror of the Linux Kernel's audit repository

Collection of Google Cloud solution examples and operational utilities for audit log monitoring, DLP de-identification, encryption key management,…

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR