
siem-threat-detection-lab
Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…

Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…

A high interaction SSH honeypot

Check if a IP is from tor or is a malicious proxy


IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

The SOC Analysts all-in-one CLI tool to automate and speed up workflow.

Online hash checker for Virustotal and other services

A modular Python application to pull intelligence about malicious files

This little tool is to calculate a MurmurHash value of a favicon to hunt phishing websites on the Shodan platform.

A Pythonic interface and command line tool for interacting with the InQuest Labs API.

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

Open YARA scan- and search engine

A tool to support the reporting of Authenticode Certificates by reducing the effort on individuals to report.