
LinuxCatScale
Incident Response collection and processing scripts with automated reporting scripts

Incident Response collection and processing scripts with automated reporting scripts

Zero-code K8s sidecar for log sanitization. Detects secrets via Entropy Analysis, preserves JSON integrity, and redacts PII deterministically. 🛡️


An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

A Software as a Service (SaaS) log collection framework.

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Automated threat hunting and incident response tool for Windows Event Logs with Sigma rule integration, real-time detection, and forensic artifact…

Mapping Corelight or Zeek data to Elastic Common Schema fields

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

Turn Rootly incidents, alerts, and teams into a queryable knowledge graph. Visualize service dependencies, on-call coverage gaps, and cross-incident…

Converts Sigma detection rules into OpenSearch Lucene and PPL queries, including alerting Monitor Rules and correlation support for SIEM detection…

Cyber Threat Defense World Modeling

Mapping Corelight or Zeek data to Elastic Common Schema logs

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

This is a repo for fetching Applocker event log by parsing the win-event log

An open-source, single-script CVE scanner for RMM-managed fleets. Pure PowerShell 7 — joins your RMM software inventory against NVD, CISA KEV, EPSS…