Endpoint visibility and DFIR.
Tools for endpoints
Workstations, servers and EDR-managed devices.
122 tools indexed
Memory forensics framework.
Vuls
—Agent-less Linux vulnerability scanner.
Open-source EDR for Windows.
Open-source XDR and SIEM.
Windows privilege-escalation enumerator.
YARA
—Pattern matching for malware research.
Community YARA rule repository.
Yeti
—Open-source threat-intel platform.
High-speed forensic feature extractor.
Encrypted C2 over DNS.
Capture SSL/TLS plaintext with eBPF.
GPU-accelerated password recovery.
Linux privesc enumeration script.
Windows credential extraction.
Generate NTLMv2 hash theft files.
SQL-powered endpoint visibility.
pspy
—Spy on Linux processes without root.
Mimikatz in pure Python.
Radare2 plug-in for Frida.
rage
—Modern file encryption with age.
SSH server and client config auditor.
Easy SSH honeypot.
Transparent SSH bastion.