
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…


Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM…

This is the development tree. Production downloads are at:

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Free hands-on digital forensics labs for students and faculty

JA4+ is a suite of network fingerprinting standards

Standalone Windows VM malware sandbox running capemon, with GUI triage viewer, YARA signatures, IOC extraction, network analysis, and…

Malware Configuration And Payload Extraction

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…