
scripts
Collection of Python and Perl scripts for digital forensics, incident response, and network analysis, including hash signature tooling and packet…

Collection of Python and Perl scripts for digital forensics, incident response, and network analysis, including hash signature tooling and packet…

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

A flow-based network monitor with Deep Packet Inspection

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

Zeek support for Community ID flow hashing.

Bro analyzer that detects Google's QUIC protocol

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!


Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Dshell is a network forensic analysis framework.

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management