
netstat2neo4j
create cypher create statements for neo4j out of netstat files from multiple machines

create cypher create statements for neo4j out of netstat files from multiple machines

Active Directory Forensic Toolkit : Detect & reconstruct AD attacks from Windows event logs (EVTX)

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

This repository demonstrates a machine learning pipeline for detecting MITRE ATT&CK techniques from logs and enriching the output using a local LLM.

Strip credential-like content from free-form strings before they reach logs or telemetry. Part of the phpboyscout Go toolkit. ·…

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

Extract useful information from PANOS support file for CVE-2024-3400

iOS Airborne vulnerabilities log artifact extractor from LogArchive CVE-2025-24252

Audit Guide for the Citrix ADC Vulnerability CVE-2019-19871. Collected from multiple sources and threat assessments. Will be updated as new methods…

I was presented with a high-severity alert indicating a potential exploit attempt of CVE-2023-22515, a zero-day vulnerability in Atlassian…

Real-world patching workflow for CVE-2025-32709. From hotfix install to SIEM alert validation—this repo documents every step with screenshots,…

A hands on lab investigating CVE-2025-39507 from a Tier 1 SOC analyst perspective. Includes log review in Microsoft Sentinel, IP analysis, real world…

Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)

Create actionable data from your Vulnerability Scans

This project aims to compare and evaluate the telemetry of various EDR products.

Open-source security framework for real-time event tracking, threat detection, and risk scoring. Monitors user behavior, detects fraud, bot attacks,…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.