cyberstars
cyberstars / purpose / blue-team

Outils pour blue team

Defensive monitoring, detection and response.

119 tools indexed

Vendor-agnostic detection rules.

MonitorAnalyzeEndpointsNetworks
PythonDRL-1.1

Local-first threat hunting over logs you already have

MonitorAnalyzeNetworksCloud
PythonMIT

Cross-platform network traffic monitor with threat detection

MonitorAnalyzeNetworks
RustApache-2.0

Open-source IPS, next generation.

MonitorInterceptNetworks
C++GPL-2.0

CVE intelligence and exploit lookup CLI.

ReconAnalyzeNetworksEndpoints
PythonMIT

Build vulnerable instrumented labs.

AutomateExploitEndpointsNetworks
PythonApache-2.0

High-performance IDS / IPS.

MonitorInterceptNetworks
CGPL-2.0

Sigma-based threat hunting and timeline generator for cloud logs.

AnalyzeMonitorCloud
RustAGPL-3.0

All-in-one honeypot platform.

MonitorAnalyzeNetworksEndpoints
PythonGPL-3.0

Wireshark on the command line.

InterceptAnalyzeNetworks
CGPL-2.0

Zero-trust access for SSH, K8s and more.

HardenMonitorNetworksCloud
GoAGPL-3.0

eBPF-based runtime security.

MonitorHardenCloudEndpoints
GoApache-2.0

Open-source SIRP for incident response.

AutomateMonitorEndpointsNetworks
ScalaAGPL-3.0

Open-source cloud-native protection platform.

ScanMonitorCloudIaC
JavaScriptApache-2.0

Honeytoken tripwire for the Shai-Hulud npm worm.

MonitorSource codeEndpoints
PythonApache-2.0

Collaborative forensic timeline analysis platform.

AnalyzeEndpoints
PythonApache-2.0

Container and IaC vulnerability scanner.

ScanCloudIaC
GoApache-2.0

UAC

Unix-like artifact collector.

AnalyzeMonitorEndpoints
ShellApache-2.0

Zero-install cross-platform incident response and DFIR toolkit.

AnalyzeMonitorEndpoints
GoMIT

Endpoint visibility and DFIR.

MonitorAnalyzeEndpoints
GoAGPL-3.0

Vuls

Agent-less Linux vulnerability scanner.

ScanEndpointsCloud
GoGPL-3.0