
prowler
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.

Modular network scanning framework that integrates diverse tools and external databases to detect vulnerabilities and configuration errors, producing…

Query high-fidelity cloud detections for known threat actors across AWS, Azure, and GCP using CloudTrail logs and custom threat intelligence rules.

OS-level monitor for AI agents: observes processes, file access, and network activity on the local machine and attributes each event to an agent…

Open-source email filtering framework that detects spam and phishing using content analysis, header checks, Bayesian scoring, and DNS blocklists.

Windows-based C2 research tool that uses Spotify playlists as a command channel and Telegram for output delivery, demonstrating cloud-assisted…

Provides rapid triage and summarization of malware samples and threat indicators, highlighting key behavioral and contextual details for analysts.

Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and…

SOC operations content for Microsoft Sentinel, including hunting queries, incident response playbooks, and security event analysis for Azure cloud…

Community-maintained database of security advisories for Ruby gems and runtimes, providing structured CVE/GHSA data with patched versions for…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring…

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

😱 A curated list of amazingly awesome OSINT

AI IR Overlay™ — practical incident response framework for AI agents in production. Built on NIST SP 800-61 r3, mapped to NIST AI RMF, NIST CSF 2.0,…

Cyber threat intelligence platform for SSL certificate discovery, domain/URL scanning, data leak monitoring, tracking link generation, and threat…