
hawk
Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

Basic log analysis tool to detect impossible travel via IP address geographic information

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.


Artifact collection tool for *nix systems

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

SECMON is a web-based tool for the automation of infosec watching and vulnerability management with a web interface.


Bash tool used for proactive detection of malicious activity on macOS systems.

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

Repo containing all info, scripts, etc. related to CVE-2021-44228

SentinelStream AI: A professional SIEM and SOAR platform featuring real-time threat correlation for CVE-2024-21410 and automated incident response…


A python package for use in generating fake data for SOC and security automation.

ThreatSentry AI is an intelligent threat hunting dashboard that leverages machine learning to proactively identify and prioritize risks in your…

Extract useful information from PANOS support file for CVE-2024-3400

Restructured and Collaborated SIEM and CVSS Infrastructure. Presented at Blackhat Asia Arsenal 2020.