cyberstars
cyberstars / purpose / blue-team

Outils pour blue team

Defensive monitoring, detection and response.

110 tools indexed

Malicious-traffic detection system.

MonitorInterceptNetworks
PythonMIT

Open-source security data lake on AWS.

MonitorAnalyzeCloudNetworks
RustApache-2.0

Nmap

The classic network mapper and port scanner.

ScanReconNetworksEndpoints
CNPSL

Open adversarial exposure validation.

AutomateMonitorEndpointsNetworks
JavaMIT

Open cyber threat intelligence platform.

AnalyzeAutomateNetworksEndpoints
TypeScriptApache-2.0

Decentralized, modular honeypot.

MonitorNetworksEndpoints
PythonBSD-3-Clause

Evaluate IAM permissions in AWS.

AnalyzeReconCloud
PythonAGPL-3.0

C++ library for packet capture and crafting.

InterceptAnalyzeNetworks
C++Unlicense

Active Directory health audit.

ScanHardenActive Directory
C#Proprietary

Open-source AI agent firewall for MCP and agent egress.

InterceptMonitorWeb appsNetworks
GoApache-2.0

BloodHound reporting for defenders.

AnalyzeAutomateActive Directory
PythonGPL-3.0

Live PowerShell disk forensics.

AnalyzeEndpoints
C#MIT

Multi-cloud security posture.

ScanHardenCloud
PythonApache-2.0

Endgame's ATT&CK simulation framework.

AutomateExploitEndpoints
PythonCustom

Self-hosted open-source WAF.

MonitorHardenWeb apps
GoApache-2.0

Python packet manipulation library.

InterceptAnalyzeNetworksWireless
PythonGPL-2.0

Multi-cloud security auditing.

ScanHardenCloud
PythonGPL-2.0

Open SOC distribution.

MonitorAnalyzeNetworksEndpoints
ShellCustom

Remote SSH for the edge.

HardenMonitorNetworksEndpoints
TypeScriptApache-2.0

Open-source SOAR.

AutomateMonitorNetworksEndpoints
JavaScriptAGPL-3.0

Vendor-agnostic detection rules.

MonitorAnalyzeEndpointsNetworks
PythonDRL-1.1

Local-first threat hunting over logs you already have

MonitorAnalyzeNetworksCloud
PythonMIT

Cross-platform network traffic monitor with threat detection

MonitorAnalyzeNetworks
RustApache-2.0

Open-source IPS, next generation.

MonitorInterceptNetworks
C++GPL-2.0