
Incident-Response-Powershell
PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and…

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

analyze a web-based network traffic 🕶 to detect central command and control servers

Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

Detection content for CVE-2026-22557 — UniFi Network Application unauthenticated path traversal (CVSS 10.0). Includes YARA, Sigma, KQL, Splunk SPL,…

TheLightScope

Android Connections Forensics

Tools and Techniques for Blue Team / Incident Response

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Detect Tactics, Techniques & Combat Threats


This is the development tree. Production downloads are at:

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.