
hawk
Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

The Sigma command line interface based on pySigma

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

XDP Based Lightweight and Fast Firewall

A Zeek OpenVPN protocol analyzer, based on Spicy.


Investigation of a PAN-OS CVE-2024-3400 command injection attempt, analyzing payload delivery, internal processing, and execution validation based on…

High fidelity defensive security lab simulating a DoD aligned enterprise network with Active Directory, VLAN segmentation, STIG based hardening,…

A headless , scriptable, command-line based MITM proxy designed for network traffic interception, analysis, and modification on Windows systems.

CarbonBlack hunting queries to detect PrintNightmare (CVE-2021-1675) exploitation via file, module load, and process events, based on Sigma rules.

Linux vulnerability scanner based on Salt Open and Vulners audit API, with Slack notifications and JIRA integration

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Investigate malicious Windows logon by visualizing and analyzing Windows event log

A machine learning toolkit for log-based anomaly detection [ISSRE'16]

Next-Gen GUI-based WiFi and Bluetooth Analyzer for Linux
