
Winshark
A wireshark plugin to instrument ETW

A wireshark plugin to instrument ETW

Corelight@Home script

A Zeek OpenVPN protocol analyzer, based on Spicy.

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Automated IP ban service that detects failed login attempts from event logs and files, blocking attackers on Windows and Linux via firewall…

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

Parses Apple Unified Logs to extract process, thread, activity, timestamp, and message metadata from logarchives or live macOS systems into JSONL/CSV…

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Rules generated from our investigations.

Universal mobile devtool for Agents & Humans - control iOS Simulators, Android Emulators, and real devices from a single dashboard and CLI

A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV output from…

Sigma rules from Joe Security

Data from a BRAWL Automated Adversary Emulation Exercise

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from…