Vendor-agnostic detection rules.
Tools for blue team
Defensive monitoring, detection and response.
119 tools indexed
Local-first threat hunting over logs you already have
Cross-platform network traffic monitor with threat detection
Open-source IPS, next generation.
CVE intelligence and exploit lookup CLI.
Build vulnerable instrumented labs.
Cloud adversary emulation.
High-performance IDS / IPS.
Sigma-based threat hunting and timeline generator for cloud logs.
Battle-tested Sysmon configuration.
Microsoft's Sysmon, on Linux.
All-in-one honeypot platform.
Wireshark on the command line.
Zero-trust access for SSH, K8s and more.
eBPF-based runtime security.
Open-source SIRP for incident response.
Open-source cloud-native protection platform.
Honeytoken tripwire for the Shai-Hulud npm worm.
Collaborative forensic timeline analysis platform.
Container and IaC vulnerability scanner.
UAC
—Unix-like artifact collector.
Zero-install cross-platform incident response and DFIR toolkit.
Endpoint visibility and DFIR.
Vuls
—Agent-less Linux vulnerability scanner.