
RemotePSpy
Live monitoring tool for remote PowerShell sessions using ETW to capture and decode WinRM/PSRP protocol, providing command execution traces and…

Live monitoring tool for remote PowerShell sessions using ETW to capture and decode WinRM/PSRP protocol, providing command execution traces and…

Automated AI powered Facebook intelligence tool for target profiling, network analysis and threat reporting. Runs entirely on-device via Ollama.…

AI-powered dark web OSINT tool that uses LLMs to refine queries, filter search results, and generate investigation summaries with a web UI and Docker…

Provenance-aware Linux kernel vulnerability research harness used in the investigation of CVE-2026-53075

Interactive data visualization tool for blue teams to analyze detection data, understand relationships, reduce alert fatigue, and improve incident…

authorized CYBERDUDEBIVASH ECOSYSTEM tool for detecting CVE-2026-23550 in WordPress Modular DS plugin

Tool to search for IOCs related to HAFNIUM: CVE-2021-26855 CVE-2021-26857 CVE-2021-26858 CVE-2021-27065

Advanced Static malware analyzer that reveals 8 injection techniques, critical API calls, hidden strings, exports PE sections (.text, .rdata) as…

Clusters and elements to attach to MISP events or attributes (like threat actors)

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation.…

Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

A Feature Rich Modular Malware Configuration Extraction Utility for MalDuck

Passive hostname, domain and IP lookup tool for non-robots

A Pythonic interface and command line tool for interacting with the InQuest Labs API.

Tools developed by the Zscaler ThreatLabz Threat Intelligence team

Extracts and decrypts malware configuration data from captured samples, automating C2 endpoint discovery, credential extraction, and indicator triage…