Super-timelining for forensics.
Tools for endpoints
Workstations, servers and EDR-managed devices.
142 tools indexed
Live PowerShell disk forensics.
PowerShell post-exploitation framework.
Linux port of Sysinternals Procmon.
PowerShell AD post-exploitation.
Endgame's ATT&CK simulation framework.
BloodHound-style privilege-escalation path mapping for Linux.
Abuse Exchange services from the outside.
Asynchronous C2 powered by DLR runtimes.
Find and exploit sudo misconfigurations.
Analyze Windows sandboxes.
Offline Exploit-DB CLI.
Open SOC distribution.
Payload generation framework.
.NET post-exploitation library.
Remote SSH for the edge.
Open-source SOAR.
Vendor-agnostic detection rules.
Local-first threat hunting over logs you already have
Open-source adversary emulation framework.
Find juicy files on Windows shares.
Social-engineering attack framework.
CVE intelligence and exploit lookup CLI.
Build vulnerable instrumented labs.