
buttinsky
Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

Modular malware analysis artifact collection and correlation framework

Privacy-first behavioral intelligence framework for multi-platform analysis and sociodynamic research.

Hermes — an ephemeral, Docker-powered OSINT framework for testing, tinkering, and secure investigative automation.

AMBER ICI v5: local-first Ollama investigative command center with case-scoped evidence, agent chains, hybrid retrieval, streaming analysis, graph…

Detects malicious IPv4 addresses and domain names associated with a web application by comparing against local threat intelligence lists of known…

DDWPasteRecon tool will help you identify code leak, sensitive files, plaintext passwords, password hashes. It also allow member of SOC & Blue Team…

This repository provides a practical comparison of breach intelligence, dark web monitoring, and identity exposure services, with a focus on factors…

This is part of a module for the framework that i'm constantly developing. Currently only information of the C2 are disclosed here.

In the realm of cybersecurity, accurately identifying and characterizing web servers is crucial for threat detection, vulnerability assessment, and…

Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…

Training-free anomaly detection framework using Shannon Entropy, Fisher Information, and Wasserstein Distance to map system states into geometrically…

Real-time OSINT intelligence dashboard: 7 live data sources (aircraft, AIS vessels, seismic, fires, weather, GDELT events, news) on an interactive…

Professional cybersecurity assessment demonstrating vulnerability identification, CVSS severity scoring, MITRE ATT&CK framework application, and…

SECMON is a web-based tool for the automation of infosec watching and vulnerability management with a web interface.

EXIST is a web application for aggregating and analyzing cyber threat intelligence.

A Python package to interact with the Mitre ATT&CK Framework

🕵️♂️ Collect a dossier on a person by username from 6K websites