


KQL para deteccion de CVE-2025-21333 en Sentinel



CitrixBleed 2 NetScaler honeypot logs

Ransomware leak site monitoring

DPS' Lightweight Investigation Notebook

StalkPhish - The Phishing kits stalker, harvesting phishing kits for investigations.

Distributed alerting for the masses!

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Curated collection of Microsoft Sentinel KQL queries and tutorials for hunting threats, analyzing Azure AD sign-in logs, detecting anomalies, and…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Indicators of Compromise from Amnesty International's cyber investigations

Composable command-line toolkit for malware triage and binary analysis: decode, decrypt, carve, and extract indicators from malicious files and…

Scan files or process memory for CobaltStrike beacons and parse their configuration

Defanged Indicator of Compromise (IOC) Extractor.