
tenzir
Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

SQL powered operating system instrumentation, monitoring, and analytics.

A Software as a Service (SaaS) log collection framework.

A repository of sysmon configuration modules

Detect Tactics, Techniques & Combat Threats

Spip network sensor written in Go

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

Some of my KQL hunting queries

Mapping Corelight or Zeek data to Elastic Common Schema logs

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

This repository contains a list of new remediation scripts.

Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

This package extends the Intel package to log more fields

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.