-
Trawler Public
PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.
-
LogBoost Public
Convert a variety of log formats to CSV while enriching detected IPs with Geolocation, ASN, DNS, WhoIs, Shodan InternetDB and Threat Indicator matches.
-
differ Public
An easy-to-use, cross-platform utility for capturing and diffing file system metadata snapshots.
-
RetrievIR Public
PowerShell script designed to help Incident Responders collect forensic evidence from local and remote Windows devices.
-
-
AuthMap Public
Authentication Mapper - helping blue-teams analyze authentication activity in Active Directory networks.
-
VTC - Velociraptor Timeline Creator
-
velociraptor-docs Public
Forked from Velocidex/velociraptor-docsDocumentation site for Velociraptor
HTML Other UpdatedApr 4, 2024 -
crackdown Public
Helping Incident Responders hunt for potential persistence mechanisms on UNIX-based systems.
-
YARACheck Public
Update and use YARA rules from across the Internet against targeted files or directories.
-
awesome-threat-intelligence Public
Forked from hslatman/awesome-threat-intelligenceA curated list of Awesome Threat Intelligence resources
-
-
-
demo-react-flask-mui-auth Public
Example React app utilizing MaterialUI with Flask JWT-authed API backend.
-
-
WMIHunter Public
Asynchronous Remote Evidence Retrieval for rapid network-wide threat hunting
-
-
-
-
ThreatSim Public
Threat Simulator for Enterprise Networks
-
-
LogonGrabber Public
Remote retrieval, filtering and analysis of Security.evtx logs for user activity analysis.
-
-
-
Outlooked-IOC Public
Tool for scanning an Outlook Inbox in order to discover Indicators of Compromise - intelligence dissemination/bulletins, *-ISAC Threads, etc,
-
-
-
-
-
PortCheck Public
Use TCP or UDP to check connection availability for remote hosts