
RedELK
Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝


Microsoft Threat Intelligence Security Tools

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting…

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

Easy automated vulnerability scanning, reporting and analysis

A modular, skill-based autonomous Security Operations Center (SOC) agent that monitors OpenSearch/Elasticsearch data, builds RAG-based behavioral…

A python package for use in generating fake data for SOC and security automation.

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

Primary data pipelines for intrusion detection, security analytics and threat hunting

AI agent set for cloud security purple teaming, runs inside Claude Code, Gemini CLI, and Codex.

Mounts AWS resources as a local filesystem for infrastructure exploration, security auditing, and configuration analysis using standard Unix tools…

Zeek log enrichment tool that adds host information and known entity references to enhance network security monitoring and incident response.

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

IDS/IPS lab for detecting and preventing Apache ActiveMQ RCE (CVE-2023-46604) using GVM, Nmap, Snort, iptables, and UFW.