
iLEAPP
Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

Real-time monitoring and slowlog analysis for Valkey and Redis databases with anomaly detection, ACL auditing, and Prometheus metrics export.

Android Logs Events And Protobuf Parser

Multi-threaded Windows event log forensics timeline generator and threat hunting tool with full Sigma rule support, producing CSV/JSON timelines for…

The Sigma command line interface based on pySigma

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

A Fast (and safe) parser for the Windows XML Event Log (EVTX) format

SQL powered operating system instrumentation, monitoring, and analytics.

Audits Windows event log settings against best-practice guidelines and Sigma-rule detectability, with automated configuration for DFIR readiness.

Security Governance for Agentic AI

Adaptive two-stage Layer 4 DDoS mitigation gateway using behavioral traffic analysis, Random Forest classification, and kernel-level ipset/iptables…

Curated collection of threat hunting and detection queries for CrowdStrike Falcon (CQL) and Microsoft Defender XDR (KQL), mapped to MITRE ATT&CK…

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

Rapidly Search and Hunt through Windows Forensic Artefacts
