This is your work, valued
S1EM. This project is a SIEM with SIRP and Threat Intel, all in one.
★ 463ZVELK. Shell
★ 4connector-euvd. Connecteur EUVD for OpenCTI
★ 2S1EM-agent. a little conf for S1EM
★ 1connector-assemblyline. Connecteur AssemblyLine for OpenCTI
★ 1connector-vigilintel. Connecteur VigilIntel for OpenCTI
★ 1connector-rosti. Connector Rosti for OpenCTI
★ 1connector-assemblyline-import. Connector OpenCTI/AssemblyLine for Import
★ 1misp-warninglist-to-assemblyline. Python
★ 1misp-warninglist-to-opencti. Misp Warning List for OpenCTI
★ 1assemblyline-service-misp-warninglists. This Assemblyline service runs in the REVIEW stage and checks submission tag values against PyMISPWarningLists.
★ 1sigmacatch. Capture real Windows events and match them against Sigma rules to produce regression data
★ 3misp-warninglist-to-assemblyline. Python
★ 1connector-rosti. Connector Rosti for OpenCTI
★ 1connector-vigilintel. Connecteur VigilIntel for OpenCTI
★ 1connector-assemblyline-import. Connector OpenCTI/AssemblyLine for Import
★ 1connector-euvd. Connecteur EUVD for OpenCTI
★ 2VigilIntel. Dans le cadre de l’amélioration continue des capacités de veille cyber, ce projet vise à fournir une synthèse quotidienne des menaces émergentes à partir de sources ouvertes fiables, notamment via l’agrégation de flux RSS spécialisés.
★ 14connector-assemblyline. Connecteur AssemblyLine for OpenCTI
★ 1CVE2CAPEC. Generate MITRE ATT&CK and D3FEND from a list of CVEs. Database with CVE, CWE, CAPEC, MITRE ATT&CK D3FEND and ATLAS Techniques data is updated daily. Showcased at BlackHat Europe 2025 Arsenal.
★ 311EDR-Telemetry. This project aims to compare and evaluate the telemetry of various EDR products.
★ 2kcolander. Case, knowledge management and digital investigation platform
★ 32osquery-packs-and-dashboards.
★ 8cvelistV5. CVE cache of the official CVE List in CVE JSON 5 format
★ 2.9kbasicgopot. Honeypot for file uploads. Written in Go.
★ 16velocistack. JavaScript
★ 54aria2-onion-downloader. Download from .onion-domains faster.
★ 245assemblyline-service-triage-sandbox. Python
★ 5crawley. The unix-way web crawler
★ 340ZVELK. Shell
★ 4TeamsPhisher. Send phishing messages and attachments to Microsoft Teams users
★ 1.1kSilkETW. C#
★ 852gpt4all. GPT4All: Run Local LLMs on Any Device. Open-source and available for commercial use.
★ 77kconnectors. OpenCTI Connectors
★ 567assemblyline. AssemblyLine 4: File triage and malware analysis
★ 522secubian-wiki.
★ 1secubian. SECUBIAN is a French Linux distribution focused on evidence processing during Incident Response.
★ 6Wazuh-Rules. Advanced Wazuh Rules for more accurate threat detection. Feel free to implement within your own Wazuh environment, contribute, or fork!
★ 1.4kvelociraptor. Digging Deeper....
★ 4.1kCortex-Analyzers. Cortex Analyzers Repository
★ 2dagda. a tool to perform static analysis of known vulnerabilities, trojans, viruses, malware & other malicious threats in docker images/containers and to monitor the docker daemon and running docker containers for detecting anomalous activities
★ 1.2kstoq. An open source framework for enterprise level automated analysis.
★ 392simplewall. Simple tool to configure Windows Filtering Platform (WFP) which can configure network activity on your computer.
★ 8.7kCVE-2021-21974. POC for CVE-2021-21974 VMWare ESXi RCE Exploit
★ 185catalyst. ⚡️ Catalyst is a self-hosted, open source incident response platform and ticket system that helps to automate alert handling and incident response processes
★ 536malware-exquacker-modules. Python
★ 5karton. Distributed malware processing framework based on Python, Redis and S3.
★ 475aurora. Malware similarity platform with modularity in mind.
★ 79littlenavmap. Little Navmap is a free flight planner, navigation tool, moving map, airport search and airport information system for Flight Simulator X, Microsoft Flight Simulator 2020, Prepar3D and X-Plane.
★ 1.6kDFIRMindMaps. A repository of DFIR-related Mind Maps geared towards the visual learners!
★ 552mercator. Mapping the information system / Cartographie du système d'information
★ 542honeymail. SMTP honeypot written in Golang
★ 33Zircolite-Rules. Sigma rules converted for direct use with Zircolite
★ 15IRM.
★ 175EVTX-ETW-Resources. Event Tracing For Windows (ETW) Resources
★ 433Microsoft-eventlog-mindmap. Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...
★ 1.1kdetection-rules. Python
★ 2.7kEnableWindowsLogSettings. Documentation and scripts to properly enable Windows event logs.
★ 714RedEye. RedEye is a visual analytic tool supporting Red & Blue Team operations
★ 2.8kchangedetection.io. Best and simplest tool for website change detection, web page monitoring, and website change alerts. Perfect for tracking content changes, price drops, restock alerts, and website defacement monitoring—all for free or enjoy our SaaS plan!
★ 33kelsec_dr2an. Script to create MITRE ATT&CK Navigator layers from the annotated detection rules in Elastic Security (Kibana).
★ 19IOCmite. Create dataset for suricata with indicators of MISP instances and add sightings in MISP if an indicator of dataset generates an alert
★ 37sliver. Adversary Emulation Framework
★ 12kail-framework. AIL framework - Analysis Information Leak framework
★ 983PoC-CVE-2022-30190. POC CVE-2022-30190 : CVE 0-day MS Offic RCE aka msdt follina
★ 157freki. :wolf: Malware analysis platform
★ 446YAFRA. YAFRA is a semi-automated framework for analyzing and representing reports about IT Security incidents.
★ 27multiscanner. Modular file scanning/analysis framework
★ 620static_file_analysis. Analysis of file (doc, pdf, exe, ...) in deep (emmbedded file(s)) with clamscan and yara rules
★ 51CVE-2022-1388. POC for CVE-2022-1388
★ 230sigmai. Import specific data sources into the Sigma generic and open signature format.
★ 79deepdarkCTI. Collection of Cyber Threat Intelligence sources from the deep and dark web
★ 7.1kWatcher. Watcher - Open Source AI-powered Cyber Threat Intelligence & Hunting Platform. Developed with Django & React JS.
★ 1.4kstoq-plugins-public. stoQ Public Plugins
★ 71malware-traffic. Download all packet captures from http://malware-traffic-analysis.net/
★ 1malware-traffic. Download all packet captures from http://malware-traffic-analysis.net/
★ 20dsiem. Security event correlation engine for ELK stack
★ 446S1EM. This project is a SIEM with SIRP and Threat Intel, all in one.
★ 1praeco. Elasticsearch alerting made simple.
★ 578bento. The minimalist, elegant and hackable startpage.
★ 2.2kdfir-iris-misp-timesketch. Scripts to integrate DFIR-IRIS, MISP and TimeSketch
★ 37awesome-honeypots. an awesome list of honeypot resources
★ 10kkarton-config-extractor. Static configuration extractor for the Karton framework
★ 10DFIR-Laptop. Installation of all the tools for a stand-alone DFIR laptop
★ 5DFIRArtifactMuseum. The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact validation processes as well as increase access to artifacts that may no longer be readily available anymore.
★ 661ChooseYourSIEMAdventure. Python
★ 18sigma-cli. The Sigma command line interface based on pySigma
★ 202Shuffle. Shuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.
★ 2.4kWinshark. A wireshark plugin to instrument ETW
★ 592ThePhish. ThePhish: an automated phishing email analysis tool
★ 1.4kGreedyBear. Threat Intel Platform for T-POTs
★ 201DFIR_Linux_Collector. The Linux DFIR Collector is a stand-alone collection tool for Gnu / Linux. Dump artifacts in json format with very few impacts on the host system. Created for incident response Team.
★ 32Malcolm. Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
★ 2.5kiris-web. Collaborative Incident Response platform
★ 1.5kSOC-OpenSource. This is a Project Designed for Security Analysts and all SOC audiences who wants to play with implementation and explore the Modern SOC architecture.
★ 743opencti. Open Cyber Threat Intelligence Platform
★ 9.8kyarGen. yarGen is a generator for YARA rules
★ 1.8kGrafiki. Threat Hunting tool about Sysmon and graphs
★ 342Yara-Repo. A script to collect (the most famous) Yara rules from more than 150 free resources. Free alternative to: https://valhalla.nextron-systems.com/
★ 28DailyIOC. IOC from articles, tweets for archives
★ 318EVTX-to-MITRE-Attack. Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.
★ 639evtx-nom. Offline/File based EVTX Ingest for Elasticsearch (ECS) and more, no Windows required
★ 1lufi-docker. Docker Image for Lufi, it means Let's Upload that FIle. It's a E2E encrypted file sharing software.
★ 5PcapMonkey. PcapMonkey will provide an easy way to analyze pcap using the latest version of Suricata and Zeek.
★ 167clamav-unofficial-sigs. ClamAV Unofficial Signatures Updater maintained by eXtremeSHOK.com
★ 554sysmon-auto-install. Install and auto update scripts for sysmon and winlogbeat
★ 3APTSimulator. A toolset to make a system look as if it was the victim of an APT attack
★ 2.8ktpotce. 🍯 T-Pot - The All In One Multi Honeypot Platform 🐝
★ 9.4kLab-DFIR-SOC. Shell
★ 70mwdb-core. Malware repository component for samples & static configuration with REST API interface.
★ 391sigma. Main Sigma Rule Repository
★ 11kDFIRLab. DFIRLab / Plateforme d'investigation numérique
★ 15Zircolite. A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
★ 838MISP2memcached. Load MISP events into memcached for log enrichment using logstash
★ 12S1EM. This project is a SIEM with SIRP and Threat Intel, all in one.
★ 463