
RemotePSpy
Live monitoring tool for remote PowerShell sessions using ETW to capture and decode WinRM/PSRP protocol, providing command execution traces and…

Live monitoring tool for remote PowerShell sessions using ETW to capture and decode WinRM/PSRP protocol, providing command execution traces and…

Automated AI powered Facebook intelligence tool for target profiling, network analysis and threat reporting. Runs entirely on-device via Ollama.…

AI-powered dark web OSINT tool that uses LLMs to refine queries, filter search results, and generate investigation summaries with a web UI and Docker…

Provenance-aware Linux kernel vulnerability research harness used in the investigation of CVE-2026-53075

Interactive data visualization tool for blue teams to analyze detection data, understand relationships, reduce alert fatigue, and improve incident…

Tool to search for IOCs related to HAFNIUM: CVE-2021-26855 CVE-2021-26857 CVE-2021-26858 CVE-2021-27065

Clusters and elements to attach to MISP events or attributes (like threat actors)

A tool to support the reporting of Authenticode Certificates by reducing the effort on individuals to report.

Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

ntroducing Search_CVE: Unleash the Power of CVE Searching Search_CVE is a cutting-edge tool designed to simplify and optimize the process of…

Zeek log enrichment tool that adds host information and known entity references to enhance network security monitoring and incident response.

Build and manage Trivy vulnerability databases by aggregating security advisories from NVD, Red Hat, Debian, and more. A CLI tool and library for…

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

CVE-2026-34197

OWASP tool for systematic threat modeling using the Model Context Protocol to identify and mitigate security risks in software architecture.

Securekit is a protocol-agnostic security kernel that enforces zero-trust, sandboxed execution for AI tool use. It sits between any LLM or agent…