
ARTIF
An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

Artifact collection tool for *nix systems

Primary data pipelines for intrusion detection, security analytics and threat hunting

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

Turn Rootly incidents, alerts, and teams into a queryable knowledge graph. Visualize service dependencies, on-call coverage gaps, and cross-incident…

gundog - guided hunting in Microsoft Defender

create cypher create statements for neo4j out of netstat files from multiple machines

Bash tool used for proactive detection of malicious activity on macOS systems.

Basic log analysis tool to detect impossible travel via IP address geographic information

Post-Exploitation EVTX Analyzer for BloodHound Mapping

Top DNS Measurement for Bro

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual…


a terminal UI to browse bbot reports

A Zeek OpenVPN protocol analyzer plugin.