cyberstars / tools / sigwood
Sigwood
—Local-first threat hunting over logs you already have
View on GitHub
PythonMIT
Command-line threat-hunting tool that surfaces suspicious activity in Zeek, Pi-hole, syslog and CloudTrail logs with no database or daemon. Ships detections for periodic C2 beaconing (via FFT), DGA/DNS tunneling, port scans, long-lived connections and anomalous AWS API activity.