
QLOG
ETW-based Windows process creation logger that enriches events with file hashes, signatures, and parent process details, outputting to Windows…

ETW-based Windows process creation logger that enriches events with file hashes, signatures, and parent process details, outputting to Windows…

An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what…

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

Azure-based client inventory and drift detection tool that collects Windows configuration data (antivirus, patching, Bitlocker) into LogAnalytics for…

Finds the detection rules in your SIEM that are running blind

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

Silent session recorder for Claude Code that logs every action, flags dangerous commands (rm -rf, sudo, curl|sh), and provides timeline review, risk…

A Bro package to identify connections that are bursting (lots of data and transferring quickly).

Bro analyzer that detects Google's QUIC protocol

fail2ban filter that catches attacks againts log4j CVE-2021-44228

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

Lightweight scanner that detects vulnerable Log4j versions and Log4Shell (CVE-2021-44228) indicators in a filesystem tree.

High-speed Windows forensic triage platform that orchestrates the Hayabusa engine to transform raw EVTX logs into prioritized threat timelines with…

BlockGuard is a Windows Data Loss Prevention (DLP) agent that intercepts and controls file access at the process level. It ensures that only…

Network monitoring tool that maps process-to-network connections, identifies cloud providers, and detects beaconing activity

IFRIT is an AI-powered reverse proxy that intercepts incoming requests in real time, classifying each one as legitimate or malicious. Legitimate…

Reproducible incident micro-postmortem for on-prem Microsoft SharePoint “ToolShell” (CVE-2025-53770): ATT&CK snapshot, “logs that matter” table,…

ThreatSentry AI is an intelligent threat hunting dashboard that leverages machine learning to proactively identify and prioritize risks in your…