
SOC-Multitool
A powerful and user-friendly browser extension that streamlines investigations for security professionals.

A powerful and user-friendly browser extension that streamlines investigations for security professionals.

Collecting & Hunting for IOCs with gusto and style

Detect and respond to Cobalt Strike beacons using ETW.

Build a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI

A honey token manager and alert system for AWS.

A Software as a Service (SaaS) log collection framework.

Collects and organizes malware indicators of compromise (IOCs) for rapid threat detection, incident response, and actionable intelligence sharing.

Detect and log CVE-2019-19781 scan and exploitation attempts.

Artifact collection tool for *nix systems

Detection-as-code platform that automates cloud security incident response by correlating artifacts, analyzing IOCs, and orchestrating…

Curated Indicators of Compromise and YARA rules from Zscaler ThreatLabz public reports for threat hunting, malware research, and detection…

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

Automated threat hunting and incident response tool for Windows Event Logs with Sigma rule integration, real-time detection, and forensic artifact…

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

Turn Rootly incidents, alerts, and teams into a queryable knowledge graph. Visualize service dependencies, on-call coverage gaps, and cross-incident…

IoCs and YARA rules from Threatray's Threat Research