
Mortimer
A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Parses Apple Unified Logs to extract process, thread, activity, timestamp, and message metadata from logarchives or live macOS systems into JSONL/CSV…

A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV output from…

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Downloads and aggregates CVSS, EPSS, and CISA known exploited vulnerability data into unified JSON/CSV files and a SQLite database. Enriches…

Small example repo for looking into log4j CVE-2021-44228

Turn Rootly incidents, alerts, and teams into a queryable knowledge graph. Visualize service dependencies, on-call coverage gaps, and cross-incident…

Converts Sigma detection rules into OpenSearch Lucene and PPL queries, including alerting Monitor Rules and correlation support for SIEM detection…

Azure-based client inventory and drift detection tool that collects Windows configuration data (antivirus, patching, Bitlocker) into LogAnalytics for…

Generates and maintains Azure Sentinel parser for Sysmon events, normalizing all Windows endpoint telemetry into a searchable log schema via…

High-speed Windows forensic triage platform that orchestrates the Hayabusa engine to transform raw EVTX logs into prioritized threat timelines with…

Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows…

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

ETW and WPP tracing tool for security research. Subscribes to multiple providers, auto-parses events to JSON, and supports advanced filtering,…


Audit Preference Pane and Log Reader for OS X

Corelight or Zeek Elastic Common Schema Templates