cyberstars
cyberstars / purpose / blue-team

Tools for blue team

Defensive monitoring, detection and response.

95 tools indexed

Make a system look as if it was hit by an APT.

AutomateExploitEndpoints
BatchfileApache-2.0

Navigate and annotate MITRE ATT&CK.

AnalyzeAutomateEndpointsNetworks
TypeScriptApache-2.0

Safely simulate malicious network traffic.

AutomateMonitorNetworks
GoBSD-3-Clause

File triage and malware analysis pipeline.

AnalyzeAutomateBinariesEndpoints
PythonMIT

Small, portable ATT&CK detection tests.

AutomateExploitEndpointsNetworks
CMIT

Cloud forensics for Azure / O365.

AnalyzeMonitorCloud
PowerShellGPL-3.0

Web-based SSH bastion and key manager.

HardenMonitorNetworksEndpoints
JavaPSL

Active Directory attack-path graphing.

AnalyzeReconActive DirectoryCloud
TypeScriptApache-2.0

Cloud-native open-source WAF.

MonitorHardenWeb appsCloud
PythonAGPL-3.0

Malware sandbox + payload extraction.

AnalyzeBinaries
PythonGPL-3.0

CISA's DFIR tool.

AnalyzeScanEndpoints
PythonCustom

Tripwire tokens for free.

MonitorEndpointsNetworks
PythonMIT

Hunt across Windows event logs at speed.

AnalyzeMonitorEndpoints
RustGPL-3.0

Visualize AWS environments.

AnalyzeReconCloud
JavaScriptBSD-3-Clause

Observable analysis engine for TheHive.

AnalyzeAutomateNetworksEndpoints
ScalaAGPL-3.0

Medium-interaction SSH/Telnet honeypot.

MonitorAutomateNetworksEndpoints
PythonBSD-3-Clause

Hunt PowerShell attacks in Windows logs.

AnalyzeMonitorEndpointsActive Directory
PowerShellBSD-3-Clause

Automated detection lab environment.

AutomateMonitorEndpointsActive Directory
HTMLMIT

Forensic artifact framework from Fox-IT.

AnalyzeEndpointsBinaries
PythonAGPL-3.0

Network forensic analysis framework.

AnalyzeNetworks
PythonCustom

SSH tarpit that wastes attacker time.

MonitorNetworksEndpoints
CBSD-Source-Code

FAME

Malware analysis automation.

AnalyzeAutomateBinaries
PythonGPL-3.0

FIR

Fast Incident Response platform.

AutomateMonitorEndpointsNetworks
PythonGPL-3.0

Ban hosts that fail auth too often.

MonitorHardenEndpointsNetworks
PythonGPL-2.0