
FalconHound
Automated BloodHound graph updater for blue teams. Enriches AD attack paths with real-time session, group, and CVE data from SIEMs, enabling…

Automated BloodHound graph updater for blue teams. Enriches AD attack paths with real-time session, group, and CVE data from SIEMs, enabling…

Collects and analyzes AD and Azure AD authentication logs to detect lateral movement attacks using graph-based anomaly detection, visualizing…

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

Read-only PowerShell module for detecting UNC2452 and other threat actor artifacts in Azure AD, auditing federated domains, service principals,…

ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.