eBPF-based runtime security.
Tools for endpoints
Workstations, servers and EDR-managed devices.
135 tools indexed
Filesystem forensics library.
Open-source SIRP for incident response.
Cross-platform data-protection framework.
Honeytoken tripwire for the Shai-Hulud npm worm.
Collaborative forensic timeline analysis platform.
PowerShell downgrade attack.
UAC
—Unix-like artifact collector.
Defeat Windows User Account Control.
Zero-install cross-platform incident response and DFIR toolkit.
Endpoint visibility and DFIR.
Memory forensics framework.
Vuls
—Agent-less Linux vulnerability scanner.
Open-source EDR for Windows.
Open-source XDR and SIEM.
Windows privilege-escalation enumerator.
YARA
—Pattern matching for malware research.
Community YARA rule repository.
Yeti
—Open-source threat-intel platform.
High-speed forensic feature extractor.
Encrypted C2 over DNS.
Capture SSL/TLS plaintext with eBPF.
GPU-accelerated password recovery.
Linux privesc enumeration script.