
RedELK
Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

ToolShell scanner - CVE-2025-53770 and detection information

quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual…

a terminal UI to browse bbot reports

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

Cloud Templates & Patterns collection <= 1.2.2 - Sensitive Information Exposure via Log File

This script is used to perform a fast check if your server is possibly affected by CVE-2021-44228 (the log4j vulnerability).

HonSSH is designed to log all SSH communications between a client and server.

A script that helps you understand why your E-Mail ended up in Spam

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

This repository contains a list of new remediation scripts.

Parses Snaffler output file and generate beautified outputs.

Primary data pipelines for intrusion detection, security analytics and threat hunting

Turn Rootly incidents, alerts, and teams into a queryable knowledge graph. Visualize service dependencies, on-call coverage gaps, and cross-incident…

create cypher create statements for neo4j out of netstat files from multiple machines