
RedELK
Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Automated infosec watching and vulnerability management tool with CVE polling, CPE-based matching, exploit search, RSS threat feed aggregation, and…

PowerShell-based guided hunting tool for Microsoft 365 Defender that automates alert triage, entity enrichment, and IOC lookups across email and…

Python tool for iOS forensic analysis that extracts files, logs, SQLite databases, and decompresses .plist files from jailbroken devices via SSH.

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

Bash tool used for proactive detection of malicious activity on macOS systems.

Zeek log enrichment tool that adds host information and known entity references to enhance network security monitoring and incident response.

Turn Rootly incidents, alerts, and teams into a queryable knowledge graph. Visualize service dependencies, on-call coverage gaps, and cross-incident…

Zeek plugin for detecting and parsing OpenVPN traffic (UDP/TCP with TLS), extracting session and TLS handshake metadata for network security…

Passive DNS honeypot that captures unsolicited queries using Unbound, Loki, Prometheus, and Grafana. Logs client IPs, queried domains, and throughput…

Probabilistic measurement script for Bro/Zeek that tracks top DNS queries by type over configurable intervals, logging results to a dedicated log for…

Lightweight low-interaction network honeypot sensor that captures TCP payloads, performs passive TLS/HTTP/SSH fingerprinting, and outputs structured…

Terminal UI for browsing, annotating, and analyzing BBOT reconnaissance scan results with live refresh, vulnerability tracking, and hierarchical…

PowerShell-based scanner to detect Log4j CVE-2021-44228 vulnerability by searching directories and log files for exploitation indicators.

Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.

Zeek script that enriches DNS logs with ICANN TLD, domain, and subdomain fields, and marks trusted domains for threat detection.

SSH honeypot proxy that logs all client-server communications for capturing attacker interactions and session data in high-interaction honeypot…

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.