
SysmonConfigPusher2
Web-based tool for managing and deploying Sysmon configurations across Windows endpoints via agentless (WMI/SMB) or agent-based methods, with remote…

Web-based tool for managing and deploying Sysmon configurations across Windows endpoints via agentless (WMI/SMB) or agent-based methods, with remote…

Automated cloud security auditing tool that detects AK/SK credential misuse by periodically auditing cloud platform logs using anomaly detection,…

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

ESF modular ingestion tool for development and research.

Azure-based client inventory and drift detection tool that collects Windows configuration data (antivirus, patching, Bitlocker) into LogAnalytics for…

Basic log analysis tool to detect impossible travel via IP address geographic information

Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078

Zeek log enrichment tool that adds host information and known entity references to enhance network security monitoring and incident response.

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600

USB port access control tool for Debian with whitelist management, automatic background scanning daemon, and CLI interface to block or allow USB…

Network monitoring tool that maps process-to-network connections, identifies cloud providers, and detects beaconing activity

Kusto query-based detection and analysis tool for CVE-2021-44228 (Log4Shell) vulnerability, enabling rapid log hunting and exploitation…

Audix is a PowerShell tool to quickly configure the Windows Event Audit Policies for security monitoring

Extensible Azure Security Tool - Documentation