
gibson
Network monitoring tool that maps process-to-network connections, identifies cloud providers, and detects beaconing activity

Network monitoring tool that maps process-to-network connections, identifies cloud providers, and detects beaconing activity

Automated data flow platform for processing and distributing data with built-in provenance tracking, secure configuration, and scalable pipeline…

Automated data flow processing and distribution system with secure configuration, provenance tracking, and extensible plugin architecture for…

ETW-based Windows process creation logger that enriches events with file hashes, signatures, and parent process details, outputting to Windows…

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

Sigma rule for detecting exploitation of CVE-2022-30190 (Follina) via Windows process creation events, enabling SOC teams to identify malicious…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

** DISPUTED ** 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the…

BlockGuard is a Windows Data Loss Prevention (DLP) agent that intercepts and controls file access at the process level. It ensures that only…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

CarbonBlack hunting queries to detect PrintNightmare (CVE-2021-1675) exploitation via file, module load, and process events, based on Sigma rules.

ThreatSentry AI is an intelligent threat hunting dashboard that leverages machine learning to proactively identify and prioritize risks in your…

Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis,…

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

OSTE WLA automate the process of analyzing web server logs with the Python Web Log Analyzer.

The Intelligent Process Lifecycle of Active Cyber Defenders