
WhoDat
Pivotable Reverse WhoIs / PDNS Fusion with Registrant Tracking & Alerting plus API for automated queries (JSON/CSV/TXT)

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

Scans jar, war, and ear files for the presence of JndiLookup.class to detect applications vulnerable to CVE-2021-44228 (Log4Shell).

Audix is a PowerShell tool to quickly configure the Windows Event Audit Policies for security monitoring

OpenIOC rules to facilitate hunting for indicators of compromise

You didn't think I'd go and leave the blue team out, right?

Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and…

Dshell is a network forensic analysis framework.

Best Practice Auditd Configuration

Incident Response collection and processing scripts with automated reporting scripts

AI 驱动的 SOC 仿真平台

A repository to release detection rules to the public

C# wrapper for ETW that serializes kernel and user-mode event data to JSON for threat hunting, malware analysis, and incident response, with Yara…

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

This project aims to compare and evaluate the telemetry of various EDR products.

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…