cyberstars
cyberstars / purpose / blue-team

Outils pour blue team

Defensive monitoring, detection and response.

95 tools indexed

Dynamic network analysis for malware.

InterceptAnalyzeNetworksBinaries
PythonApache-2.0

Runtime security for containers.

MonitorCloudEndpoints
C++Apache-2.0

Open vulnerability management platform.

AutomateMonitorNetworksEndpoints
PythonGPL-3.0

Adversary tradecraft detection on Windows.

MonitorAnalyzeEndpoints
GoApache-2.0

Osquery-powered device management.

MonitorHardenEndpoints
GoMIT

Open log management.

MonitorAnalyzeNetworksEndpoints
JavaSSPL-1.0

HELK

The Hunting ELK stack.

MonitorAnalyzeEndpointsNetworks
Jupyter NotebookGPL-3.0

Windows hardening for high-risk users.

HardenEndpoints
GoGPL-3.0

Windows event log threat hunter.

AnalyzeMonitorEndpoints
RustAGPL-3.0

Open-source adversary emulation platform.

AutomateExploitNetworksEndpoints
PythonGPL-3.0

Manage threat intel at scale.

AnalyzeAutomateNetworksEndpoints
PythonAGPL-3.0

Visualize Windows logon events.

AnalyzeMonitorActive DirectoryEndpoints
PythonMIT

Loki

Simple IOC and YARA scanner.

ScanAnalyzeEndpoints
PythonGPL-3.0

Linux / macOS / Unix security auditor.

ScanHardenEndpoints
ShellGPL-3.0

MISP

Threat intelligence sharing platform.

AutomateAnalyzeNetworksEndpoints
PHPAGPL-3.0

Automated adversary emulation.

AutomateExploitEndpointsNetworks
PythonApache-2.0

Microsoft Threat Intelligence in Python.

AnalyzeAutomateCloudEndpoints
PythonMIT

Malicious-traffic detection system.

MonitorInterceptNetworks
PythonMIT

Open-source security data lake on AWS.

MonitorAnalyzeCloudNetworks
RustApache-2.0

Nmap

The classic network mapper and port scanner.

ScanReconNetworksEndpoints
CNPSL

Open adversarial exposure validation.

AutomateMonitorEndpointsNetworks
JavaMIT

Open cyber threat intelligence platform.

AnalyzeAutomateNetworksEndpoints
TypeScriptApache-2.0

Decentralized, modular honeypot.

MonitorNetworksEndpoints
PythonBSD-3-Clause