Battle-tested Sysmon configuration.
Outils pour endpoints
Workstations, servers and EDR-managed devices.
142 tools indexed
Microsoft's Sysmon, on Linux.
All-in-one honeypot platform.
Send phishing via Microsoft Teams.
Zero-trust access for SSH, K8s and more.
eBPF-based runtime security.
Filesystem forensics library.
Open-source SIRP for incident response.
Cross-platform data-protection framework.
Honeytoken tripwire for the Shai-Hulud npm worm.
Collaborative forensic timeline analysis platform.
PowerShell downgrade attack.
UAC
—Unix-like artifact collector.
Defeat Windows User Account Control.
Zero-install cross-platform incident response and DFIR toolkit.
Endpoint visibility and DFIR.
Memory forensics framework.
Vuls
—Agent-less Linux vulnerability scanner.
Open-source EDR for Windows.
Open-source XDR and SIEM.
Windows privilege-escalation enumerator.
YARA
—Pattern matching for malware research.
Community YARA rule repository.
Yeti
—Open-source threat-intel platform.