
scripts
Collection of Python and Perl scripts for digital forensics, incident response, and network analysis, including hash signature tooling and packet…

Collection of Python and Perl scripts for digital forensics, incident response, and network analysis, including hash signature tooling and packet…

pySigma OpenSearch backend

The Sigma command line interface based on pySigma

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

Zeek support for Community ID flow hashing.

A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further…

Chronicle parser for CORELIGHT and related information.

Corelight or Zeek Elastic Common Schema Templates

Easy automated vulnerability scanning, reporting and analysis

Zero-trust anti-forensic HTTP client. Wipes secrets. Severs traces. CPR in a Stealth Tank. 👻

Enhanced SSH client with TUI — manage connections, keys, and sessions

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Collection of forensic tools

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…