


SQL powered operating system instrumentation, monitoring, and analytics.

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Build a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

Automated threat hunting and incident response tool for Windows Event Logs with Sigma rule integration, real-time detection, and forensic artifact…

gundog - guided hunting in Microsoft Defender

ToolShell scanner - CVE-2025-53770 and detection information

Basic log analysis tool to detect impossible travel via IP address geographic information

Post-Exploitation EVTX Analyzer for BloodHound Mapping

Spip network sensor written in Go

This package extends the Intel package to log more fields