
Sooty
The SOC Analysts all-in-one CLI tool to automate and speed up workflow.

The SOC Analysts all-in-one CLI tool to automate and speed up workflow.

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Online hash checker for Virustotal and other services

A high interaction SSH honeypot

A modular Python application to pull intelligence about malicious files

This little tool is to calculate a MurmurHash value of a favicon to hunt phishing websites on the Shodan platform.

Check if a IP is from tor or is a malicious proxy

A tool to support the reporting of Authenticode Certificates by reducing the effort on individuals to report.

A Pythonic interface and command line tool for interacting with the InQuest Labs API.

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

Open YARA scan- and search engine

A tool for simplifying the process of researching IOCs.


Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…