
ALFA
Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…

Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…

Script to check if system are vulnable to cve-2026-23111

Multi-engine Linux malware scanner with five detection stages (MD5, HEX pattern, YARA, ClamAV, statistical), real-time inotify monitoring,…

Semantic Observability for UNIX Systems - A lightweight C-based system prober with AI-powered analysis

Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis,…

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Open Source Intelligence Interface for Deep Web Scraping

A tool to perform various OSINT techniques, aggregate all the raw data, visualise it on a dashboard, and facilitate alerting and monitoring on the…

Web-Scale NoSQL Idempotent Cloud-Native Big-Data Serverless Plaintext Credential Search

Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally

Hardened Debian-based privacy OS with pre-integrated anonymity stack (Tor, VPN, DNSCrypt), anti-forensic tooling, SOC security center, and standalone…

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

A terminal based tool that monitors real-time Bitcoin transactions above or below a specified threshold.

SECMON is a web-based tool for the automation of infosec watching and vulnerability management with a web interface.

Runtime vulnerability scanner: finds CVEs in the services actually running on a host and ranks them by network exposure.

Purpleteam scripts simulation & Detection - trigger events for SOC detections

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…