
fastnetmon
Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

You didn't think I'd go and leave the blue team out, right?



Best Practice Auditd Configuration

Community-driven project for documenting, standardizing, and modeling security event logs to improve detection analytics and data normalization…

Easy automated vulnerability scanning, reporting and analysis

Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and…

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

A Software as a Service (SaaS) log collection framework.

Sysmon configuration file template with default high-quality event tracing

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Blue Team detection lab created with Terraform and Ansible in Azure.

Data from a BRAWL Automated Adversary Emulation Exercise


An open standard for hashing network flows into identifiers, a.k.a "Community IDs".