
LogonTracer
Investigate malicious Windows logon by visualizing and analyzing Windows event log

Investigate malicious Windows logon by visualizing and analyzing Windows event log

A containerized enterprise-style lab for researching and defending against CVE-2026-27483.

Windows-based C2 research tool that uses Spotify playlists as a command channel and Telegram for output delivery, demonstrating cloud-assisted…

AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK…

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

Network-based passive DNS logger capturing and logging DNS queries from live traffic or pcap files, outputting JSON for integration with SIEM and…

A query aggregator for OSINT based threat hunting

A terminal based tool that monitors real-time Bitcoin transactions above or below a specified threshold.

PowerShell-based Windows Server Security Audit Engine by Cyb3rint3l Labs. Measures alignment with the NIS2 directive and maps findings to MITRE…

Apache Real Time Logs Analyzer System

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

An AI-powered threat modeling tool that leverages OpenAI's GPT models to generate threat models for a given application based on the STRIDE…

STIX 2.1 collections of the MITRE ATT&CK knowledge base, providing adversary tactics and techniques for enterprise, mobile, and ICS threat…

Public IoCs about log4j CVE-2021-44228

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)

Curated directory of threat intelligence sources, feeds, frameworks, tools, and research for SOC/CTI teams—covering IOCs, STIX/TAXII formats, and…