
LinuxCatScale
Incident Response collection and processing scripts with automated reporting scripts

Incident Response collection and processing scripts with automated reporting scripts

A collection of scripts which may come in handy during your freedom fighting activities.

Collection of Python and Perl scripts for digital forensics, incident response, and network analysis, including hash signature tooling and packet…

An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what…

Automated secret and leak detection scanner for GitHub and paste sites, with heuristic filtering, IOL enrichment via Shhgit/TruffleHog, and ELK-based…

This repository contains a list of new remediation scripts.

quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual…

ThreatSentry AI is an intelligent threat hunting dashboard that leverages machine learning to proactively identify and prioritize risks in your…

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Detect Tactics, Techniques & Combat Threats

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Automated adversary emulation (Caldera) against an AD lab to validate Sigma detection coverage and map results to MITRE ATT&CK.

Automated threat hunting and incident response tool for Windows Event Logs with Sigma rule integration, real-time detection, and forensic artifact…

Detection Script for MongoBleed Exploitation

Adaptive two-stage Layer 4 DDoS mitigation gateway using behavioral traffic analysis, Random Forest classification, and kernel-level ipset/iptables…

Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs