
fastnetmon
Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Corelight or Zeek Elastic Common Schema Templates

Chronicle parser for CORELIGHT and related information.

Enhanced SSH client with TUI — manage connections, keys, and sessions

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Collection of forensic tools

Easy automated vulnerability scanning, reporting and analysis

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

The Sigma command line interface based on pySigma

Zeek support for Community ID flow hashing.

pySigma OpenSearch backend

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

Zero-trust anti-forensic HTTP client. Wipes secrets. Severs traces. CPR in a Stealth Tank. 👻

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further…

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Collection of Python and Perl scripts for digital forensics, incident response, and network analysis, including hash signature tooling and packet…