
arkime
Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

A script that helps you understand why your E-Mail ended up in Spam

Kvasir: Penetration Test Data Management

Passive DNS Capture and Monitoring Toolkit

The OWASP SecureTea Project provides a one-stop security solution for various devices (personal computers / servers / IoT devices)

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

SOC operations content for Microsoft Sentinel, including hunting queries, incident response playbooks, and security event analysis for Azure cloud…

Build a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI

The Sigma command line interface based on pySigma

Artifact collection tool for *nix systems

Automated threat hunting and incident response tool for Windows Event Logs with Sigma rule integration, real-time detection, and forensic artifact…

Downloads and aggregates CVSS, EPSS, and CISA known exploited vulnerability data into unified JSON/CSV files and a SQLite database. Enriches…

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

Primary data pipelines for intrusion detection, security analytics and threat hunting

MITRE ATT&CK mapped queries for SentinelOne Deep Visiblity