
grove
A Software as a Service (SaaS) log collection framework.

A Software as a Service (SaaS) log collection framework.

Artifact collection tool for *nix systems

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

Automated threat hunting and incident response tool for Windows Event Logs with Sigma rule integration, real-time detection, and forensic artifact…

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

Turn Rootly incidents, alerts, and teams into a queryable knowledge graph. Visualize service dependencies, on-call coverage gaps, and cross-incident…

Indicator of Compromise Scanner for CVE-2019-19781

OpenIOC rules to facilitate hunting for indicators of compromise

Bash tool used for proactive detection of malicious activity on macOS systems.

An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what…

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

A Simple Log4j Indicator of Compromise Linux Detector

ToolShell scanner - CVE-2025-53770 and detection information

quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual…

Detection of Manjusaka C2 framework

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool

Some of my KQL hunting queries