
packetsifterTool
PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

MAPS cloud scanner and response parser for Microsoft Defender research.

analyze a web-based network traffic 🕶 to detect central command and control servers

Detects active domain mutations to prevent phishing and smishing. Uses IANA TLDs, blockchain DNS validation, and DoH malware reports. Outputs JSON or…

Intelligent threat hunter and phishing servers

Detection Script for MongoBleed Exploitation

NCC Group research repository with decoding scripts, Yara and Suricata signatures for APT15 (Royal APT) malware, enabling beacon analysis and command…

Turn Rootly incidents, alerts, and teams into a queryable knowledge graph. Visualize service dependencies, on-call coverage gaps, and cross-incident…

This Repository Talks about the Follina MSDT from Defender Perspective

Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.

Generates efficient IPv4 blocklists from Zeek network flows using multiple prioritization models (new, consistent, random forest) to identify…

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

Simple IP Information Tools for Reputation Data Analysis

A graphing toolkit for threat research - and other things

This is a mirror of a forked repository. It adds several features to gitrob including GitLab support, commit content searching, in-memory repository…

Defense Against the Shai-Hulud Supply Chain Attack

Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner