Security Operations
227 projecten in Beveiliging & identiteit
Toont top 200 van 227 op Atlas Score; verfijn met de filters hierboven.
pentagi
@vxcontrolFully autonomous AI Agents system capable of performing complex penetration testing tasks
open-kritt
@Kritt-aiOpen-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code.
vuls
@future-architectAgent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices
Shuffle
@ShuffleShuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.
deepdarkCTI
@fastfireCollection of Cyber Threat Intelligence sources from the deep and dark web
AiSOC
@beenuarOpen-source AI Security Operations Center: alert fusion, LLM-agent triage, MITRE ATT&CK investigation, and a replayable decision ledger for every agent step. Self-hostable, runs with no API keys, MIT licensed. Ships an MCP server for Claude, Cursor and Continue.
strix
@usestrixOpen-source AI penetration testing tool to find and fix your app’s vulnerabilities.
IntelOwl
@intelowlprojectIntelOwl: manage your Threat Intelligence at scale
hayabusa
@Yamato-SecurityHayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
tracecat
@TracecatHQOpen-source security automation platform for teams and AI agents
CyberStrike
@CyberStrikeusOpen-source AI-powered offensive security harness for automated penetration testing.
user-scanner
@kaifcodec🕵️♂️ (2-in-1) Email & Username OSINT suite featuring native MCP support for deep data extraction just from a single Email/Username. Analyzes 1080+ actively maintained scan vectors (200+ email / 880+ username) for security research, investigations, and digital footprinting.
iris-web
@dfir-irisCollaborative Incident Response platform
maltrail
@stamparmMalicious traffic detection system
ossec-hids
@ossecOSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.
APT-Hunter
@ahmedkhliefAPT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity
kunai
@kunai-projectThreat-hunting tool for Linux
awesome-soc
@cyb3rxpA curated knowledge base to build, run and mature a SOC (including CSIRT).
gosec
@securegoGo security checker
MISP
@MISPMISP (core software) - Open Source Threat Intelligence and Sharing Platform
dependency-track
@DependencyTrackDependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
voidaccess
@KatrielMosesSelf-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and Flare.
cve-mcp-server
@mukul975Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.
osint-brazuca
@osintbrazucaRepositório criado com intuito de reunir informações, fontes(websites/portais) e tricks de OSINT dentro do contexto Brasil.
laurel
@threathunters-ioTransform Linux Audit logs for SIEM usage
MemProcFS-Analyzer
@LETHAL-FORENSICSMemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR
ScubaGear
@cisagovAutomation to assess the state of your M365 tenant against CISA's baselines
fame
@certsocietegeneraleFAME Automates Malware Evaluation
SIEM
@TonyPhippsSIEM Tactics, Techiques, and Procedures
capa
@mandiantThe FLARE team's open-source tool to identify capabilities in executable files.
stratus-red-team
@DataDog:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud
agent
@PentesterFlowAgentic offensive-security in your terminal
opensquat
@atenreiroopenSquat is an open-source tool that detects look-alike domains impersonating your brand, by scanning newly registered domains daily.
gitGraber
@hisxogitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...
Microsoft-Analyzer-Suite
@LETHAL-FORENSICSA collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID
rekono
@pablosntOffensive security platform that automates attack surface discovery and vulnerability management
destroylist
@phishdestroyReal-time phishing & scam domain blocklist - 205k+ curated threats, 1M+ community, free API, multiple formats
FACT_core
@fkie-cadFirmware Analysis and Comparison Tool
RansomLook
@RansomLookYet another Ransomware gang tracker
osint_toolkit
@dev-luOpen source platform for cyber security analysts with many features for threat intelligence and detection engineering.
pocindex
@0xMarcioSearch 82,000+ public CVE proof-of-concept exploits from GitHub, Nuclei, ExploitDB, Metasploit and Vulhub.
intelmq
@certtoolsIntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.
Threat-Hunting-and-Detection
@Cyb3r-MonkRepository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).
tenzir
@tenzirTenzir is the data pipeline engine for security teams.
BrightIntosh
@niklasr22Unlock the full brightness of the XDR display of your MacBook Pro
Open-Source-Threat-Intel-Feeds
@Bert-JanPThis repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such as IP, URL, CVE and Hash.
recon-skills
@uphiagoRecon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh
osint-brazuca-regex
@osintbrazucaRepositório criado com intuito de reunir expressões regulares dentro do contexto Brasil
cargo-auditable
@rust-secure-codeMake production Rust binaries auditable
Cortex
@TheHive-ProjectCortex: a Powerful Observable Analysis and Active Response Engine
APTRS
@APTRSAutomated pentest reporting with custom templates, project tracking, customer dashboard and client management tools. Streamline your security workflows effortlessly!
reconmap
@reconmapReconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance through execution and reporting. With built-in command automation, output parsing, and AI‑assisted summaries, it delivers faster, more structured, and high‑quality security assessments.
Live-Forensicator
@Johnng007Cross-platform incident response and live forensics toolkit with built-in detection, structured analysis, and report generation — designed for fast, actionable security investigations.
falconpy
@CrowdStrikeThe CrowdStrike Falcon SDK for Python
flounder
@adshaoAutonomous white-hat security auditor for AI-driven code review, bug bounty research, exploit construction, and execution-grounded verification.
crowdsec-blocklist-import
@wolffcatskyy10-20x more blocks for your CrowdSec bouncers — 120k+ IPs from 32 free threat feeds
Z3r0
@Aethena-LabAI-native red-team workbench for authorized penetration testing and vulnerability research, with specialist agents, sandboxed tooling, evidence records, and replayable timelines.
pentestcode
@s0ld13rrPentestCode - Multi-agent AI penetration testing system with persistent engagement state, strategic coordination, and parallel autonomous operations.
Unit42-timely-threat-intel
@PaloAltoNetworksA collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence.
caldera
@apacheAutomated Adversary Emulation Platform
cyberbro
@stanfrbdA simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.
rita
@activecmReal Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
faction
@factionsecurityPen Test Report Generation and Assessment Collaboration
mitaka
@ninosekiA browser extension for OSINT search
flare-learning-hub
@mandiantFree educational content on reverse engineering and malware analysis from the FLARE team
KQL-threat-hunting-queries
@cyb3rmik3A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
TheBigBrother
@chadi0xThe Big Brother V7.0 is a weaponized OSINT platform featuring username enumeration (473+ platforms), quad-vector visual intelligence, Sky Radar tracking, crypto wallet analysis, SSL intelligence, digital footprint reconstruction, EXIF extraction, advanced dorking, and network reconnaissance.
Loki-RS
@Neo23x0🐍 High-performance, multi-threaded YARA & IOC scanner
IPBan
@DigitalRubySince 2011, IPBan is the worlds most trusted, free security software to block hackers and botnets. With both Windows and Linux support, IPBan has your dedicated or cloud server protected. Upgrade to IPBan Pro today and get a discount. Learn more at ↓
harpoon
@Te-kCLI tool for open source and threat intelligence
mihari
@ninosekiA query aggregator for OSINT based threat hunting
rustinel
@Karib0uEndpoint detection for Windows, Linux, and macOS. Sigma, YARA, and IOC rules on native telemetry. Written in Rust. No cloud account required.
Cortex-Analyzers
@TheHive-ProjectCortex Analyzers Repository
BLUESPAWN
@ION28An Active Defense and EDR software to empower Blue Teams
BetterDisplay
@waydabberUnlock your displays on your Mac! Flexible HiDPI scaling, XDR/HDR extra brightness, virtual screens, DDC control, extra dimming, PIP/streaming, EDID override and lots more!
Lunar
@alin23Intelligent adaptive brightness for your external monitors
sleuthkit
@sleuthkitThe Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
forensictools
@cristianzshCollection of forensic tools
xingrin
@yyhuniOpen-source attack surface management and authorized security automation platform for asset discovery, service probing, scan orchestration, and security result management.
UTMStack
@utmstackEnterprise-ready SIEM, SOAR and Compliance powered by real-time correlation and threat intelligence.
Kanvas
@WithSecureOpenSourceA simple-to-use IR (incident response) case management tool for tracking and documenting investigations.
dfir-orc
@DFIR-ORCForensics artefact collection tool for systems running Microsoft Windows
mcp-shodan
@w0h1vMCP server for Shodan — search internet-connected devices, IP reconnaissance, DNS lookups, and CVE/CPE vulnerability intelligence. Works with Claude Code, Codex, Gemini CLI, and Claude Desktop.
opencti
@OpenCTI-PlatformOpen Cyber Threat Intelligence Platform
linux-malware-detect
@rfxnMulti-engine Linux malware scanner with five detection stages (MD5, HEX pattern, YARA, ClamAV, statistical), real-time inotify monitoring, quarantine, and multi-channel alerting
velociraptor
@VelocidexDigging Deeper....
Scanners-Box
@We5terThe Ultimate Open-Source Security Arsenal for Hackers, Enterprises, and AI Agents——面向极客、企业与 AI 智能体的全域开源网络安全工具矩阵
bearer
@BearerCode security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
fibratus
@rabbitstackSecurity sensor for realtime threat detection and protection
lonkero
@bountyyfiLonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.
connectors
@OpenCTI-PlatformOpenCTI Connectors
osctrl
@jmpsecFast and efficient osquery management
misp-modules
@MISPModules for expansion services, enrichment, import and export in MISP and other tools.
EVTX-to-MITRE-Attack
@mdecrevoisierSet of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.
Zeek-Intelligence-Feeds
@CriticalPathSecurityZeek-Formatted Threat Intelligence Feeds
wazuh
@wazuhWazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
BestEdrOfTheMarket
@XaconeEDR Lab for Experimentation Purposes
assemblyline
@CybercentreCanadaAssemblyLine 4: File triage and malware analysis
api
@vulnersComOfficial Python SDK for the Vulners vulnerability-intelligence API — search CVEs, exploits and advisories (CVSS/EPSS/KEV), audit software, Linux/Windows hosts and SBOMs, and stream the whole graph. Typed sync + async clients, 100% v3-compatible, with a built-in MCP server for AI agents.
fail2ban-ui
@swissmakersFail2Ban UI is a management platform for operating Fail2Ban across one or more Linux hosts. It provides a central place to review bans, search and unban IP addresses, manage jails and filters, and receive notifications.
hunting-rules
@travisbgreenSuricata rules for network anomaly detection
agentic-threat-hunting-framework
@Nebulock-IncATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.
volatility3
@volatilityfoundationVolatility 3.0 development
Malware-Database
@cryptwareappsA large repository of malware samples with 2500+ malware samples & source codes for a variety of platforms by Cryptware Apps.
panther-analysis
@panther-labsBuilt-in Panther detection rules and policies
darknet-mcp-server
@badchars66-tool MCP server for dark web intelligence — breach data, ransomware tracking, Tor .onion access, malware analysis, blockchain intel, exploit search, stealer logs
ransomware.live
@JMousqueton🏴☠️💰 Another Ransomware gang tracker
turbinia
@googleAutomation and Scaling of Digital Forensics Tools
spiderfoot
@smicallefSpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
Hacking-Tools
@aw-junaidThis Repository is a collection of different ethical hacking tools and malware's for penetration testing and research purpose written in python, ruby, rust, c++, go and c.
agent-threat-rules
@Agent-Threat-RuleOpen detection-rule standard for AI agent security threats — like Sigma, but for AI agents. Executable, testable rules for prompt injection, tool poisoning, context exfiltration and MCP attacks. Merged into open-source projects at Microsoft, Cisco, Gen Digital, MISP and FINOS. MIT-licensed.
Ransomware-Tool-Matrix
@BushidoUKA resource containing all the tools each ransomware gangs uses
ThreatIngestor
@pedramaminiExtract and aggregate threat intelligence.
ScubaGoggles
@cisagovSCuBA Secure Configuration Baselines and assessment tool for Google Workspace
DestroyScammers
@phishdestroyScam intelligence, phishing attribution, drainer mapping. Legal OSINT only. Public data. Real cases. For researchers and victims.
signature-base
@Neo23x0YARA signature and IOC database for my scanners and tools
SubDomainizer
@nsonaniya2010A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.
Microsoft-eventlog-mindmap
@mdecrevoisierSet of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...
Incident-Response-Powershell
@Bert-JanPPowerShell Digital Forensics & Incident Response Scripts.
ScanCannon
@johnnyxmasA script for credentials-based attack surface enumeration and general reconnaissance of massive external networks
iMonitor
@wecooperateiMonitor(冰镜 - 终端行为分析系统)
PatrowlManager
@PatrowlPatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform
vigil
@Vigil-SOCVigil: The leading open source AI SOC. Apache 2.0. Runs against your own LLM, local or remote.
C2IntelFeeds
@drb-raAutomatically created C2 Feeds
dsiem
@defenxorSecurity event correlation engine for ELK stack
sectemplates
@securitytemplatesOpen source templates you can use to bootstrap your security programs
cheatsheets
@r1cksecCollection of knowledge about information security
aws-customer-playbook-framework
@aws-samplesThis repository provides sample templates for security playbooks against various scenarios when using Amazon Web Services.
acra
@cossacklabsDatabase security suite. Database proxy with field-level encryption, search through encrypted data, SQL injections prevention, intrusion detection, honeypots. Supports client-side and proxy-side ("transparent") encryption. SQL, NoSQL.
BEAR-C2
@S3N4T0R-0X0BEAR-C2 is an adversary simulation and emulation framework built around real-world TTPs inspired by Russian, Chinese, North Korean, and Iranian APT groups.
gitleaks-action
@gitleaksProtect your secrets using Gitleaks-Action
n8n-CyberSecurity-Workflows
@JoasASantosSecurity automation with n8n ideas: 100+ Red/Blue/AppSec workflows, integrations, and ready-to-run playbooks.
Yara-rules
@bartblazeCollection of private Yara rules.
misp-warninglists
@MISPWarning lists to inform users of MISP about potential false-positives or other information in indicators
misp-galaxy
@MISPClusters and elements to attach to MISP events or attributes (like threat actors)
bomber
@devops-kung-fuScans Software Bill of Materials (SBOMs) for security vulnerabilities
Malware-Bible
@Perkins-FundFree educational courses in cybersecurity, reverse engineering, malware analysis, and programming designed to expand access, build practical skills, and support the next generation of cyber defenders.
Malware-Research-Hub
@darama22Self-contained malware research hub: curated catalog of 80 families (1971-2024) + 2,764 real encrypted samples, indexed and searchable. Local Flask app, bilingual.
h1domains
@zricethezavHackerOne "in scope" domains
Matano
@matanolabsOpen source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS
MasterParser
@securityjoesMasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs
Penetration-Testing-Study-Notes
@AnasAboreedaPenetration Testing notes, resources and scripts
monkey
@guardicoreInfection Monkey - An open-source adversary emulation platform
Pi.Alert
@pucherotWIFI / LAN intruder detector. Check the devices connected and alert you with unknown devices. It also warns of the disconnection of "always connected" devices
threat-intel
@volexitySignatures and IoCs from public Volexity blog posts.
dnstwist
@elceefDomain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation
inventory
@trickestAsset inventory of over 800 public bug bounty programs.
ScamIntelLogs
@phishdestroyOpen-source intelligence archive of crypto scam operations — internal chats, admin panels, victim records, and infrastructure data for research and investigation
Awesome-FOFA
@FofaInfoThe FOFA Library collects usage tips, common scenarios, F&Q, and more for FOFA.
DefenderYara
@roadwyExtracted Yara rules from Windows Defender mpavbase and mpasbase
Elkeid
@bytedanceElkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It is derived from ByteDance's internal best practices.
CyberBlue
@cyberblu3sCyberSecurity BLUE TEAM containerized platform that brings together open-source tools for SIEM, DFIR, CTI, SOAR, and Network Analysis
misp-training
@MISPMISP trainings, threat intel and information sharing training materials with source code
Sooty
@TheresAFewConorsThe SOC Analysts all-in-one CLI tool to automate and speed up workflow.
phishing_catcher
@x0rzPhishing catcher using Certstream
ioc
@gendigitalincThreat Intel IoCs + bits and pieces of dark matter. Published by Gen Threat Labs.
response
@monzoMonzo's real-time incident response and reporting tool ⚡️
shortscan
@bitquarkAn IIS short filename enumeration tool
Yara-Rules
@advanced-threat-researchRepository of YARA rules made by Trellix ATR Team
yasuo
@0xsaubyA ruby script that scans for vulnerable & exploitable 3rd-party web applications on a network
Bashfuscator
@BashfuscatorA fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.
whids
@0xrawsecOpen Source EDR for Windows
burpgpt
@aress31A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan for discovering highly bespoke vulnerabilities and enables running traffic-based analysis of any type.
Pyramid
@naksyna tool to help operate in EDRs' blind spots
dfirtrack
@dfirtrackDFIRTrack - The Incident Response Tracking Application
SOC-Multitool
@zdhenard42A powerful and user-friendly browser extension that streamlines investigations for security professionals.
osquery-configuration
@palantirA repository for using osquery for incident detection and response
Scrummage
@matamorphosisA Holistic OSINT and Threat Hunting Platform
freki
@cristianzsh:wolf: Malware analysis platform
Aurora-Incident-Response
@cyb3rfoxIncident Response Documentation made easy. Developed by Incident Responders for Incident Responders
raven
@CycodeLabsCI/CD Security Analyzer
PurpleCloud
@iknowjasonA little tool to play with Azure Identity - Azure and Entra ID lab creation tool. Blog: https://medium.com/@iknowjason/sentinel-for-purple-teaming-183b7df7a2f4
Minimalistic-offensive-security-tools
@InfosecMatterA repository of tools for pentesting of restricted and isolated environments.
Meerkat
@TonyPhippsA collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.
baitroute
@utkusenA web honeypot library to create vulnerable-looking endpoints to detect and mislead attackers
ThreatActors-TTPs
@crocodyliRepository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving to other types of threats.
BypassAV
@matro7shThis map lists the essential techniques to bypass anti-virus and EDR
pfelk
@pfelkpfSense/OPNsense + Elastic Stack
Malware-Exhibit
@alvin-tosh🚀🚀 This is a 🎇🔥 REAL WORLD🔥 🎇 Malware Collection I have Compiled & analysed by researchers🔥 to understand more about Malware threats😈, analysis and mitigation🧐.
Open-Source-Security-Guide
@mikeroyalOpen Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.
TelemetrySourcerer
@jthuraisamyEnumerate and disable common sources of telemetry used by AV/EDR.
AzureHunter
@darkquasarA Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365
awesome-event-ids
@stuhliCollection of Event ID ressources useful for Digital Forensics and Incident Response
privatezilla
@builtbybel👀👮🐢🔥Performs a privacy & security check of Windows 10
pacbot
@tmobilePacBot (Policy as Code Bot)
pycharm-security
@tonybaloneyFinds security holes in your Python projects from PyCharm and GitHub
beagle
@yampeloBeagle is an incident response and digital forensics tool which transforms security logs and data into graphs.
iocextract
@pedramaminiDefanged Indicator of Compromise (IOC) Extractor.
incidental
@incidentalhqAn opensource incident management platform integrating with Slack.
MIDAS
@Stream-ADAnomaly Detection on Dynamic (time-evolving) Graphs in Real-time and Streaming manner. Detecting intrusions (DoS and DDoS attacks), frauds, fake rating anomalies.
atc-react
@atc-projectA knowledge base of actionable Incident Response techniques
DripLoader
@xuanxuan0Evasive shellcode loader for bypassing event-based injection detection (PoC)
psad
@mrashpsad: Intrusion Detection and Log Analysis with iptables
nosqli
@Charlie-belmerNoSql Injection CLI tool, for finding vulnerable websites using MongoDB.
RmEye
@RoomaSec戎码之眼是一个window上的基于att&ck模型的威胁监控工具.有效检测常见的未知威胁与已知威胁.防守方的利剑
theo
@cleanunicornEthereum recon and exploitation tool.
investigations
@AmnestyTechIndicators of Compromise from Amnesty International's cyber investigations
PersistenceSniper
@last-bytePowershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made with ❤️ by @last0x00 and @dottor_morte
Hawkeye
@mir1ceWindows应急响应工具---Hawkeye(鹰眼)。集Windows日志分析,进程扫描,主机信息于一体的综合应急响应分析工具
URLextractor
@eschultzeInformation gathering & website reconnaissance | https://phishstats.info/