CVE intelligence and exploit lookup CLI.
Tools for blue team
Defensive monitoring, detection and response.
110 tools indexed
Build vulnerable instrumented labs.
Cloud adversary emulation.
High-performance IDS / IPS.
Sigma-based threat hunting and timeline generator for cloud logs.
Battle-tested Sysmon configuration.
Microsoft's Sysmon, on Linux.
All-in-one honeypot platform.
Wireshark on the command line.
Zero-trust access for SSH, K8s and more.
eBPF-based runtime security.
Open-source SIRP for incident response.
Open-source cloud-native protection platform.
Honeytoken tripwire for the Shai-Hulud npm worm.
Collaborative forensic timeline analysis platform.
Container and IaC vulnerability scanner.
UAC
—Unix-like artifact collector.
Zero-install cross-platform incident response and DFIR toolkit.
Endpoint visibility and DFIR.
Vuls
—Agent-less Linux vulnerability scanner.
Open-source EDR for Windows.
Open-source XDR and SIEM.
Network protocol analyzer.
YARA
—Pattern matching for malware research.