Network forensic analysis framework.
Tools for blue team
Defensive monitoring, detection and response.
110 tools indexed
SSH tarpit that wastes attacker time.
Windows ETW provider browser and trace inspector.
FAME
—Malware analysis automation.
FIR
—Fast Incident Response platform.
Ban hosts that fail auth too often.
Dynamic network analysis for malware.
Runtime security for containers.
Open vulnerability management platform.
Adversary tradecraft detection on Windows.
Osquery-powered device management.
Security advisories + PoCs from Google.
Open log management.
HELK
—The Hunting ELK stack.
Windows hardening for high-risk users.
Windows event log threat hunter.
Open-source adversary emulation platform.
Manage threat intel at scale.
Visualize Windows logon events.
Loki
—Simple IOC and YARA scanner.
Linux / macOS / Unix security auditor.
MISP
—Threat intelligence sharing platform.
Automated adversary emulation.
Microsoft Threat Intelligence in Python.