
phantom-grid
An eBPF-powered Active Defense system that turns your Linux server into a deceptive honeypot. Features transparent traffic redirection, OS…

An eBPF-powered Active Defense system that turns your Linux server into a deceptive honeypot. Features transparent traffic redirection, OS…

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

Turn Rootly incidents, alerts, and teams into a queryable knowledge graph. Visualize service dependencies, on-call coverage gaps, and cross-incident…

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

Azure-based client inventory and drift detection tool that collects Windows configuration data (antivirus, patching, Bitlocker) into LogAnalytics for…

TheLightScope

PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs

Run on your ManageEngine server

Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.

SSH-based Linux incident response tool that executes diagnostic commands to collect network configs, logs, user accounts, and processes, then…

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Downloads and aggregates CVSS, EPSS, and CISA known exploited vulnerability data into unified JSON/CSV files and a SQLite database. Enriches…

Small example repo for looking into log4j CVE-2021-44228