
loki
Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Collection of Python and Perl scripts for digital forensics, incident response, and network analysis, including hash signature tooling and packet…

The Sigma command line interface based on pySigma

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Corelight or Zeek Elastic Common Schema Templates

Enhanced SSH client with TUI — manage connections, keys, and sessions

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Terminal UI for browsing and replaying AWS WAF v2 logs from CloudWatch, S3, and the sampling API, with YAML filtering, auth detection, and…

pySigma OpenSearch backend

Chronicle parser for CORELIGHT and related information.

An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what…

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Persists BurpSuite proxy history, Repeater requests, and Intruder payloads across sessions; exports and imports .log files for web pentesting context.

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Advanced Burp Suite Logging Extension

Zeek support for Community ID flow hashing.

Downloads and aggregates CVSS, EPSS, and CISA known exploited vulnerability data into unified JSON/CSV files and a SQLite database. Enriches…