
RsWindowsThingies
Rust-based Windows forensic toolkit for real-time MFT monitoring, event log streaming, and channel enumeration, enabling live system analysis and…

Rust-based Windows forensic toolkit for real-time MFT monitoring, event log streaming, and channel enumeration, enabling live system analysis and…

OS X Auditor is a free Mac OS X computer forensics tool

A tool to assess data quality, built on top of the awesome OSSEM.

The easiest, and most secure way to access and protect all of your infrastructure.

A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further…

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

A tool to subscribe to receive all standard Android broadcasts on your Android device.

Basic log analysis tool to detect impossible travel via IP address geographic information

Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600

Audix is a PowerShell tool to quickly configure the Windows Event Audit Policies for security monitoring

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Some tools to help mitigating Apache Log4j 2 CVE-2021-44228

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…



Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

analyze a web-based network traffic 🕶 to detect central command and control servers

Analyzes Nginx access logs to detect SQL injection, scanner tools, webshells, and exploitation attempts, aiding system administrators in server…