
msticpy
Microsoft Threat Intelligence Security Tools

Microsoft Threat Intelligence Security Tools

A list of cyber-chef recipes and curated links

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting…

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

Useful resources for SOC Analyst and SOC Analyst candidates.

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Passive DNS Capture and Monitoring Toolkit

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Blue Team detection lab created with Terraform and Ansible in Azure.

PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

PowerShell-based security toolkit for small-to-medium enterprises, providing automated alerts, Active Directory hardening, Windows Event Forwarding,…

XDP Based Lightweight and Fast Firewall