Post-exploitation framework.
Tools for endpoints
Workstations, servers and EDR-managed devices.
135 tools indexed
SSH tarpit that wastes attacker time.
Compiled language for Windows shellcode and BOFs.
Windows ETW provider browser and trace inspector.
Reverse-proxy phishing for MFA bypass.
FIR
—Fast Incident Response platform.
Ban hosts that fail auth too often.
Runtime security for containers.
Open vulnerability management platform.
Adversary tradecraft detection on Windows.
Osquery-powered device management.
Dynamic instrumentation for app analysis.
Mandiant's password-cracking frontend.
Security advisories + PoCs from Google.
Open-source phishing toolkit.
Open log management.
HELK
—The Hunting ELK stack.
Windows hardening for high-risk users.
Modern, malleable C2 framework.
Windows event log threat hunter.
Chrome/Chromium browser forensics.
IPED
—Open-source digital forensics processor.
Open-source adversary emulation platform.
Manage threat intel at scale.