
opencve
Aggregate, filter, and track CVEs from multiple sources with team collaboration, custom dashboards, alerts, and AI-powered analysis for vulnerability…

Aggregate, filter, and track CVEs from multiple sources with team collaboration, custom dashboards, alerts, and AI-powered analysis for vulnerability…

Cortex: a Powerful Observable Analysis and Active Response Engine

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan,…

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of…

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.


PatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS…

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Collection of private Yara rules.

A collection of companies that disclose adversary TTPs after they have been breached