
pySigma
Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Collection of Python and Perl scripts for digital forensics, incident response, and network analysis, including hash signature tooling and packet…

mboxShell. Fast terminal viewer for MBOX files of any size. Open, search and export emails from Gmail Takeout backups (50GB+) without loading them…

Enhanced SSH client with TUI — manage connections, keys, and sessions

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Purpleteam scripts simulation & Detection - trigger events for SOC detections

Easy-to-use live forensics toolbox for Linux endpoints

Command-line packet analyzer for network monitoring and data acquisition, capturing and displaying network traffic for troubleshooting and security…

Automated security incident response playbooks for Splunk Phantom, integrating Zeek logs, DNS analysis, and VirusTotal threat intelligence to…

A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.