Security Operations

227 projecten in Beveiliging & identiteit

Toont top 200 van 227 op Atlas Score; verfijn met de filters hierboven.

pentagi

@vxcontrol

Fully autonomous AI Agents system capable of performing complex penetration testing tasks

Zelf te hosten Commit 5 dagen geleden ★ 25.024
77 4/5 gemeten

open-kritt

@Kritt-ai

Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code.

Zelf te hosten Commit 7 dagen geleden ★ 2.174
77 4/5 gemeten

vuls

@future-architect

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

GPL-3.0 Commit 1 dag geleden ★ 12.272
76 5/5 gemeten

Shuffle

@Shuffle

Shuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.

Maintainer in de EU Commit 3 dagen geleden ★ 2.444
75 4/5 gemeten

deepdarkCTI

@fastfire

Collection of Cyber Threat Intelligence sources from the deep and dark web

GPL-3.0 Commit 3 dagen geleden ★ 7.304
72 4/5 gemeten

AiSOC

@beenuar

Open-source AI Security Operations Center: alert fusion, LLM-agent triage, MITRE ATT&CK investigation, and a replayable decision ledger for every agent step. Self-hostable, runs with no API keys, MIT licensed. Ships an MCP server for Claude, Cursor and Continue.

Zelf te hosten Commit vandaag ★ 2.371
71 4/5 gemeten

strix

@usestrix

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Apache-2.0 Commit 3 dagen geleden ★ 65.217
70 4/5 gemeten

IntelOwl

@intelowlproject

IntelOwl: manage your Threat Intelligence at scale

AGPL-3.0 Commit 5 dagen geleden ★ 4.731
70 5/5 gemeten

hayabusa

@Yamato-Security

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

AGPL-3.0 Commit 2 dagen geleden ★ 3.364
69 4/5 gemeten

tracecat

@TracecatHQ

Open-source security automation platform for teams and AI agents

AGPL-3.0 Commit 1 dag geleden ★ 3.815
69 4/5 gemeten

CyberStrike

@CyberStrikeus

Open-source AI-powered offensive security harness for automated penetration testing.

AGPL-3.0 Commit 1 dag geleden ★ 2.885
69 4/5 gemeten

user-scanner

@kaifcodec

🕵️‍♂️ (2-in-1) Email & Username OSINT suite featuring native MCP support for deep data extraction just from a single Email/Username. Analyzes 1080+ actively maintained scan vectors (200+ email / 880+ username) for security research, investigations, and digital footprinting.

MIT Commit 1 dag geleden ★ 5.018
68 4/5 gemeten

iris-web

@dfir-iris

Collaborative Incident Response platform

Maintainer in de EU Commit 3 dagen geleden ★ 1.571
68 4/5 gemeten

maltrail

@stamparm

Malicious traffic detection system

Maintainer in de EU Commit 1 dag geleden ★ 8.609
68 5/5 gemeten

ossec-hids

@ossec

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.

GPL-2.0 Commit 11 dagen geleden ★ 5.059
68 5/5 gemeten

APT-Hunter

@ahmedkhlief

APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity

GPL-3.0 Commit 8 dagen geleden ★ 1.428
68 4/5 gemeten

kunai

@kunai-project

Threat-hunting tool for Linux

Maintainer in de EU Commit 5 dagen geleden ★ 1.092
68 4/5 gemeten

awesome-soc

@cyb3rxp

A curated knowledge base to build, run and mature a SOC (including CSIRT).

Maintainer in de EU Commit 3 dagen geleden ★ 1.882
67 4/5 gemeten

gosec

@securego

Go security checker

Apache-2.0 Commit 6 dagen geleden ★ 8.954
67 5/5 gemeten

MISP

@MISP

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

AGPL-3.0 Commit 5 dagen geleden ★ 6.552
67 5/5 gemeten

dependency-track

@DependencyTrack

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

Apache-2.0 Commit 1 dag geleden ★ 4.240
67 5/5 gemeten

voidaccess

@KatrielMoses

Self-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and Flare.

Zelf te hosten Commit 2 maanden geleden ★ 743
66 4/5 gemeten

cve-mcp-server

@mukul975

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.

Maintainer in de EU Commit 10 dagen geleden ★ 1.589
66 4/5 gemeten

osint-brazuca

@osintbrazuca

Repositório criado com intuito de reunir informações, fontes(websites/portais) e tricks de OSINT dentro do contexto Brasil.

MIT Commit 10 dagen geleden ★ 2.758
65 4/5 gemeten

laurel

@threathunters-io

Transform Linux Audit logs for SIEM usage

GPL-3.0 Commit 12 dagen geleden ★ 866
65 4/5 gemeten

MemProcFS-Analyzer

@LETHAL-FORENSICS

MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR

Maintainer in de EU Commit 28 dagen geleden ★ 737
65 4/5 gemeten

ScubaGear

@cisagov

Automation to assess the state of your M365 tenant against CISA's baselines

CC0-1.0 Commit 2 dagen geleden ★ 2.684
65 4/5 gemeten

fame

@certsocietegenerale

FAME Automates Malware Evaluation

GPL-3.0 Commit 2 dagen geleden ★ 946
65 4/5 gemeten

SIEM

@TonyPhipps

SIEM Tactics, Techiques, and Procedures

GPL-3.0 Commit 5 dagen geleden ★ 731
64 4/5 gemeten

capa

@mandiant

The FLARE team's open-source tool to identify capabilities in executable files.

Apache-2.0 Commit 14 dagen geleden ★ 6.204
64 5/5 gemeten

stratus-red-team

@DataDog

:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud

Apache-2.0 Commit 4 dagen geleden ★ 2.406
64 4/5 gemeten

agent

@PentesterFlow

Agentic offensive-security in your terminal

Apache-2.0 Commit 28 dagen geleden ★ 1.378
64 4/5 gemeten

opensquat

@atenreiro

openSquat is an open-source tool that detects look-alike domains impersonating your brand, by scanning newly registered domains daily.

GPL-3.0 Commit 2 maanden geleden ★ 984
64 4/5 gemeten

gitGraber

@hisxo

gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...

GPL-3.0 Commit 6 maanden geleden ★ 2.438
63 4/5 gemeten

Microsoft-Analyzer-Suite

@LETHAL-FORENSICS

A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID

Maintainer in de EU Commit 3 maanden geleden ★ 679
63 4/5 gemeten

rekono

@pablosnt

Offensive security platform that automates attack surface discovery and vulnerability management

Maintainer in de EU Commit 1 dag geleden ★ 610
63 4/5 gemeten

destroylist

@phishdestroy

Real-time phishing & scam domain blocklist - 205k+ curated threats, 1M+ community, free API, multiple formats

MIT Commit vandaag ★ 1.853
63 4/5 gemeten

FACT_core

@fkie-cad

Firmware Analysis and Comparison Tool

GPL-3.0 Commit 3 dagen geleden ★ 1.465
63 5/5 gemeten

RansomLook

@RansomLook

Yet another Ransomware gang tracker

GPL-3.0 Commit 2 dagen geleden ★ 673
63 4/5 gemeten

osint_toolkit

@dev-lu

Open source platform for cyber security analysts with many features for threat intelligence and detection engineering.

AGPL-3.0 Commit 5 maanden geleden ★ 948
62 4/5 gemeten

pocindex

@0xMarcio

Search 82,000+ public CVE proof-of-concept exploits from GitHub, Nuclei, ExploitDB, Metasploit and Vulhub.

MIT Commit vandaag ★ 1.418
62 4/5 gemeten

intelmq

@certtools

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

AGPL-3.0 Commit 5 maanden geleden ★ 1.135
62 5/5 gemeten

Threat-Hunting-and-Detection

@Cyb3r-Monk

Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).

Maintainer in de EU Commit 2 maanden geleden ★ 822
62 4/5 gemeten

tenzir

@tenzir

Tenzir is the data pipeline engine for security teams.

Maintainer in de EU Commit 1 dag geleden ★ 762
62 4/5 gemeten

BrightIntosh

@niklasr22

Unlock the full brightness of the XDR display of your MacBook Pro

Maintainer in de EU Commit 23 dagen geleden ★ 554
62 4/5 gemeten

Open-Source-Threat-Intel-Feeds

@Bert-JanP

This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such as IP, URL, CVE and Hash.

BSD-3-Clause Commit 1 dag geleden ★ 949
61 4/5 gemeten

recon-skills

@uphiago

Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh

MIT Commit 27 dagen geleden ★ 1.280
61 4/5 gemeten

osint-brazuca-regex

@osintbrazuca

Repositório criado com intuito de reunir expressões regulares dentro do contexto Brasil

MIT Commit 1 maand geleden ★ 1.012
60 4/5 gemeten

cargo-auditable

@rust-secure-code

Make production Rust binaries auditable

Apache-2.0 Commit 15 dagen geleden ★ 860
60 4/5 gemeten

Cortex

@TheHive-Project

Cortex: a Powerful Observable Analysis and Active Response Engine

Maintainer in de EU Commit 3 maanden geleden ★ 1.630
60 5/5 gemeten

APTRS

@APTRS

Automated pentest reporting with custom templates, project tracking, customer dashboard and client management tools. Streamline your security workflows effortlessly!

MIT Commit 1 dag geleden ★ 1.078
60 4/5 gemeten

reconmap

@reconmap

Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance through execution and reporting. With built-in command automation, output parsing, and AI‑assisted summaries, it delivers faster, more structured, and high‑quality security assessments.

Apache-2.0 Commit 1 dag geleden ★ 995
60 4/5 gemeten

Live-Forensicator

@Johnng007

Cross-platform incident response and live forensics toolkit with built-in detection, structured analysis, and report generation — designed for fast, actionable security investigations.

Maintainer in de EU Commit 18 dagen geleden ★ 634
60 4/5 gemeten

falconpy

@CrowdStrike

The CrowdStrike Falcon SDK for Python

Unlicense Commit 3 dagen geleden ★ 516
60 5/5 gemeten

flounder

@adshao

Autonomous white-hat security auditor for AI-driven code review, bug bounty research, exploit construction, and execution-grounded verification.

AGPL-3.0 Commit 12 dagen geleden ★ 514
60 4/5 gemeten

crowdsec-blocklist-import

@wolffcatskyy

10-20x more blocks for your CrowdSec bouncers — 120k+ IPs from 32 free threat feeds

Zelf te hosten Commit 3 dagen geleden ★ 365
60 4/5 gemeten

Z3r0

@Aethena-Lab

AI-native red-team workbench for authorized penetration testing and vulnerability research, with specialist agents, sandboxed tooling, evidence records, and replayable timelines.

MIT Commit 15 dagen geleden ★ 910
59 4/5 gemeten

pentestcode

@s0ld13rr

PentestCode - Multi-agent AI penetration testing system with persistent engagement state, strategic coordination, and parallel autonomous operations.

MIT Commit 26 dagen geleden ★ 719
59 4/5 gemeten

Unit42-timely-threat-intel

@PaloAltoNetworks

A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence.

GPL-3.0 Commit 3 dagen geleden ★ 615
59 4/5 gemeten

caldera

@apache

Automated Adversary Emulation Platform

Apache-2.0 Commit 1 maand geleden ★ 7.292
59 4/5 gemeten

cyberbro

@stanfrbd

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

MIT Commit 3 dagen geleden ★ 690
59 4/5 gemeten

rita

@activecm

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

GPL-3.0 Commit 3 dagen geleden ★ 644
59 5/5 gemeten

faction

@factionsecurity

Pen Test Report Generation and Assessment Collaboration

GPL-2.0 Commit 18 dagen geleden ★ 605
59 4/5 gemeten

mitaka

@ninoseki

A browser extension for OSINT search

MIT Commit 11 dagen geleden ★ 1.869
58 5/5 gemeten

flare-learning-hub

@mandiant

Free educational content on reverse engineering and malware analysis from the FLARE team

Apache-2.0 Commit 6 maanden geleden ★ 1.479
58 4/5 gemeten

KQL-threat-hunting-queries

@cyb3rmik3

A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).

Maintainer in de EU Commit 4 maanden geleden ★ 798
58 4/5 gemeten

TheBigBrother

@chadi0x

The Big Brother V7.0 is a weaponized OSINT platform featuring username enumeration (473+ platforms), quad-vector visual intelligence, Sky Radar tracking, crypto wallet analysis, SSL intelligence, digital footprint reconstruction, EXIF extraction, advanced dorking, and network reconnaissance.

MIT Commit 7 dagen geleden ★ 766
58 4/5 gemeten

Loki-RS

@Neo23x0

🐍 High-performance, multi-threaded YARA & IOC scanner

Maintainer in de EU Commit 1 dag geleden ★ 360
58 4/5 gemeten

IPBan

@DigitalRuby

Since 2011, IPBan is the worlds most trusted, free security software to block hackers and botnets. With both Windows and Linux support, IPBan has your dedicated or cloud server protected. Upgrade to IPBan Pro today and get a discount. Learn more at ↓

MIT Commit 1 dag geleden ★ 2.196
58 5/5 gemeten

harpoon

@Te-k

CLI tool for open source and threat intelligence

GPL-3.0 Commit 17 dagen geleden ★ 1.294
58 5/5 gemeten

mihari

@ninoseki

A query aggregator for OSINT based threat hunting

MIT Commit 3 maanden geleden ★ 943
58 4/5 gemeten

rustinel

@Karib0u

Endpoint detection for Windows, Linux, and macOS. Sigma, YARA, and IOC rules on native telemetry. Written in Rust. No cloud account required.

Maintainer in de EU Commit 1 dag geleden ★ 495
58 4/5 gemeten

Cortex-Analyzers

@TheHive-Project

Cortex Analyzers Repository

Maintainer in de EU Commit 11 dagen geleden ★ 491
58 5/5 gemeten

BLUESPAWN

@ION28

An Active Defense and EDR software to empower Blue Teams

GPL-3.0 Commit 6 maanden geleden ★ 1.339
57 5/5 gemeten

BetterDisplay

@waydabber

Unlock your displays on your Mac! Flexible HiDPI scaling, XDR/HDR extra brightness, virtual screens, DDC control, extra dimming, PIP/streaming, EDID override and lots more!

Commit 5 dagen geleden ★ 33.838
57 4/5 gemeten

Lunar

@alin23

Intelligent adaptive brightness for your external monitors

Maintainer in de EU Commit 3 maanden geleden ★ 5.705
57 5/5 gemeten

sleuthkit

@sleuthkit

The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.

Commit 1 dag geleden ★ 3.155
57 5/5 gemeten

forensictools

@cristianzsh

Collection of forensic tools

MIT Commit 1 maand geleden ★ 704
57 4/5 gemeten

xingrin

@yyhuni

Open-source attack surface management and authorized security automation platform for asset discovery, service probing, scan orchestration, and security result management.

MIT Commit 7 dagen geleden ★ 656
57 4/5 gemeten

UTMStack

@utmstack

Enterprise-ready SIEM, SOAR and Compliance powered by real-time correlation and threat intelligence.

AGPL-3.0 Commit 1 dag geleden ★ 584
57 5/5 gemeten

Kanvas

@WithSecureOpenSource

A simple-to-use IR (incident response) case management tool for tracking and documenting investigations.

Maintainer in de EU Commit 5 maanden geleden ★ 465
57 4/5 gemeten

dfir-orc

@DFIR-ORC

Forensics artefact collection tool for systems running Microsoft Windows

Maintainer in de EU Commit 2 maanden geleden ★ 449
57 4/5 gemeten

mcp-shodan

@w0h1v

MCP server for Shodan — search internet-connected devices, IP reconnaissance, DNS lookups, and CVE/CPE vulnerability intelligence. Works with Claude Code, Codex, Gemini CLI, and Claude Desktop.

MIT Commit 20 dagen geleden ★ 173
57 4/5 gemeten

opencti

@OpenCTI-Platform

Open Cyber Threat Intelligence Platform

Commit 1 dag geleden ★ 10.055
56 5/5 gemeten

linux-malware-detect

@rfxn

Multi-engine Linux malware scanner with five detection stages (MD5, HEX pattern, YARA, ClamAV, statistical), real-time inotify monitoring, quarantine, and multi-channel alerting

GPL-2.0 Commit 4 maanden geleden ★ 1.512
56 5/5 gemeten

velociraptor

@Velocidex

Digging Deeper....

Commit 1 dag geleden ★ 4.279
55 5/5 gemeten

Scanners-Box

@We5ter

The Ultimate Open-Source Security Arsenal for Hackers, Enterprises, and AI Agents——面向极客、企业与 AI 智能体的全域开源网络安全工具矩阵

Commit 4 dagen geleden ★ 9.070
55 4/5 gemeten

bearer

@Bearer

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Commit 7 dagen geleden ★ 2.751
55 5/5 gemeten

fibratus

@rabbitstack

Security sensor for realtime threat detection and protection

Maintainer in de EU Commit 1 dag geleden ★ 2.552
55 5/5 gemeten

lonkero

@bountyyfi

Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.

Maintainer in de EU Commit 1 maand geleden ★ 1.099
55 4/5 gemeten

connectors

@OpenCTI-Platform

OpenCTI Connectors

Apache-2.0 Commit 1 dag geleden ★ 582
55 4/5 gemeten

osctrl

@jmpsec

Fast and efficient osquery management

MIT Commit 3 dagen geleden ★ 532
55 5/5 gemeten

misp-modules

@MISP

Modules for expansion services, enrichment, import and export in MISP and other tools.

AGPL-3.0 Commit 3 dagen geleden ★ 377
55 4/5 gemeten

EVTX-to-MITRE-Attack

@mdecrevoisier

Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.

CC0-1.0 Commit 4 maanden geleden ★ 645
54 4/5 gemeten

Zeek-Intelligence-Feeds

@CriticalPathSecurity

Zeek-Formatted Threat Intelligence Feeds

MIT Commit 1 dag geleden ★ 403
54 4/5 gemeten

wazuh

@wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

Commit 2 dagen geleden ★ 17.015
54 5/5 gemeten

BestEdrOfTheMarket

@Xacone

EDR Lab for Experimentation Purposes

Maintainer in de EU Commit 4 maanden geleden ★ 1.564
54 4/5 gemeten

assemblyline

@CybercentreCanada

AssemblyLine 4: File triage and malware analysis

MIT Commit 6 dagen geleden ★ 541
54 4/5 gemeten

api

@vulnersCom

Official Python SDK for the Vulners vulnerability-intelligence API — search CVEs, exploits and advisories (CVSS/EPSS/KEV), audit software, Linux/Windows hosts and SBOMs, and stream the whole graph. Typed sync + async clients, 100% v3-compatible, with a built-in MCP server for AI agents.

MIT Commit 14 dagen geleden ★ 375
54 5/5 gemeten

fail2ban-ui

@swissmakers

Fail2Ban UI is a management platform for operating Fail2Ban across one or more Linux hosts. It provides a central place to review bans, search and unban IP addresses, manage jails and filters, and receive notifications.

AGPL-3.0 Commit 14 dagen geleden ★ 356
54 4/5 gemeten

hunting-rules

@travisbgreen

Suricata rules for network anomaly detection

GPL-3.0 Commit 5 maanden geleden ★ 183
54 4/5 gemeten

agentic-threat-hunting-framework

@Nebulock-Inc

ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.

MIT Commit 1 dag geleden ★ 378
53 4/5 gemeten

volatility3

@volatilityfoundation

Volatility 3.0 development

Commit 11 dagen geleden ★ 4.441
53 5/5 gemeten

Malware-Database

@cryptwareapps

A large repository of malware samples with 2500+ malware samples & source codes for a variety of platforms by Cryptware Apps.

GPL-3.0 Commit 7 maanden geleden ★ 635
53 4/5 gemeten

panther-analysis

@panther-labs

Built-in Panther detection rules and policies

Apache-2.0 Commit 4 dagen geleden ★ 466
53 4/5 gemeten

darknet-mcp-server

@badchars

66-tool MCP server for dark web intelligence — breach data, ransomware tracking, Tor .onion access, malware analysis, blockchain intel, exploit search, stealer logs

MIT Commit 6 dagen geleden ★ 463
53 4/5 gemeten

ransomware.live

@JMousqueton

🏴‍☠️💰 Another Ransomware gang tracker

Maintainer in de EU Commit 2 maanden geleden ★ 366
53 4/5 gemeten

turbinia

@google

Automation and Scaling of Digital Forensics Tools

Apache-2.0 Commit 3 dagen geleden ★ 795
52 5/5 gemeten

spiderfoot

@smicallef

SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.

MIT Commit 6 maanden geleden ★ 22.555
52 5/5 gemeten

Hacking-Tools

@aw-junaid

This Repository is a collection of different ethical hacking tools and malware's for penetration testing and research purpose written in python, ruby, rust, c++, go and c.

Commit 1 maand geleden ★ 1.017
52 4/5 gemeten

agent-threat-rules

@Agent-Threat-Rule

Open detection-rule standard for AI agent security threats — like Sigma, but for AI agents. Executable, testable rules for prompt injection, tool poisoning, context exfiltration and MCP attacks. Merged into open-source projects at Microsoft, Cisco, Gen Digital, MISP and FINOS. MIT-licensed.

MIT Commit 1 dag geleden ★ 402
52 4/5 gemeten

Ransomware-Tool-Matrix

@BushidoUK

A resource containing all the tools each ransomware gangs uses

Commit 1 maand geleden ★ 1.451
51 4/5 gemeten

ThreatIngestor

@pedramamini

Extract and aggregate threat intelligence.

GPL-2.0 Commit 4 maanden geleden ★ 931
51 4/5 gemeten

ScubaGoggles

@cisagov

SCuBA Secure Configuration Baselines and assessment tool for Google Workspace

CC0-1.0 Commit 3 dagen geleden ★ 368
51 4/5 gemeten

DestroyScammers

@phishdestroy

Scam intelligence, phishing attribution, drainer mapping. Legal OSINT only. Public data. Real cases. For researchers and victims.

MIT Commit 15 dagen geleden ★ 362
51 4/5 gemeten

signature-base

@Neo23x0

YARA signature and IOC database for my scanners and tools

Maintainer in de EU Commit 20 dagen geleden ★ 3.038
50 5/5 gemeten

SubDomainizer

@nsonaniya2010

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

MIT Commit 14 dagen geleden ★ 1.894
50 5/5 gemeten

Microsoft-eventlog-mindmap

@mdecrevoisier

Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...

BSD-2-Clause Commit 11 maanden geleden ★ 1.103
49 4/5 gemeten

Incident-Response-Powershell

@Bert-JanP

PowerShell Digital Forensics & Incident Response Scripts.

BSD-3-Clause Commit 4 maanden geleden ★ 816
48 4/5 gemeten

ScanCannon

@johnnyxmas

A script for credentials-based attack surface enumeration and general reconnaissance of massive external networks

Commit 2 maanden geleden ★ 482
48 4/5 gemeten

iMonitor

@wecooperate

iMonitor(冰镜 - 终端行为分析系统)

AGPL-3.0 Commit 8 maanden geleden ★ 836
48 4/5 gemeten

PatrowlManager

@Patrowl

PatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform

Maintainer in de EU Commit 7 maanden geleden ★ 639
48 5/5 gemeten

vigil

@Vigil-SOC

Vigil: The leading open source AI SOC. Apache 2.0. Runs against your own LLM, local or remote.

Commit 1 dag geleden ★ 324
48 4/5 gemeten

C2IntelFeeds

@drb-ra

Automatically created C2 Feeds

Commit 1 dag geleden ★ 742
47 4/5 gemeten

dsiem

@defenxor

Security event correlation engine for ELK stack

GPL-3.0 Commit 1 maand geleden ★ 446
47 5/5 gemeten

sectemplates

@securitytemplates

Open source templates you can use to bootstrap your security programs

Commit 2 maanden geleden ★ 916
47 4/5 gemeten

cheatsheets

@r1cksec

Collection of knowledge about information security

Commit 27 dagen geleden ★ 705
46 4/5 gemeten

aws-customer-playbook-framework

@aws-samples

This repository provides sample templates for security playbooks against various scenarios when using Amazon Web Services.

Commit 1 dag geleden ★ 675
46 4/5 gemeten

acra

@cossacklabs

Database security suite. Database proxy with field-level encryption, search through encrypted data, SQL injections prevention, intrusion detection, honeypots. Supports client-side and proxy-side ("transparent") encryption. SQL, NoSQL.

Apache-2.0 Commit 5 maanden geleden ★ 1.493
46 5/5 gemeten

BEAR-C2

@S3N4T0R-0X0

BEAR-C2 is an adversary simulation and emulation framework built around real-world TTPs inspired by Russian, Chinese, North Korean, and Iranian APT groups.

Commit 6 dagen geleden ★ 682
46 4/5 gemeten

gitleaks-action

@gitleaks

Protect your secrets using Gitleaks-Action

Commit 2 maanden geleden ★ 652
45 5/5 gemeten

n8n-CyberSecurity-Workflows

@JoasASantos

Security automation with n8n ideas: 100+ Red/Blue/AppSec workflows, integrations, and ready-to-run playbooks.

MIT Commit 1 jaar geleden ★ 960
44 4/5 gemeten

Yara-rules

@bartblaze

Collection of private Yara rules.

MIT Commit 8 maanden geleden ★ 389
44 4/5 gemeten

misp-warninglists

@MISP

Warning lists to inform users of MISP about potential false-positives or other information in indicators

Commit 4 dagen geleden ★ 652
44 4/5 gemeten

misp-galaxy

@MISP

Clusters and elements to attach to MISP events or attributes (like threat actors)

Commit 3 dagen geleden ★ 642
44 5/5 gemeten

bomber

@devops-kung-fu

Scans Software Bill of Materials (SBOMs) for security vulnerabilities

MPL-2.0 Commit 8 maanden geleden ★ 627
44 4/5 gemeten

Malware-Bible

@Perkins-Fund

Free educational courses in cybersecurity, reverse engineering, malware analysis, and programming designed to expand access, build practical skills, and support the next generation of cyber defenders.

Commit 1 maand geleden ★ 612
44 4/5 gemeten

Malware-Research-Hub

@darama22

Self-contained malware research hub: curated catalog of 80 families (1971-2024) + 2,764 real encrypted samples, indexed and searchable. Local Flask app, bilingual.

Commit 17 dagen geleden ★ 635
43 4/5 gemeten

h1domains

@zricethezav

HackerOne "in scope" domains

Commit 1 dag geleden ★ 530
43 4/5 gemeten

Matano

@matanolabs

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

Apache-2.0 Commit 2 jaaren geleden ★ 1.699
42 4/5 gemeten

MasterParser

@securityjoes

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

MIT Commit 8 maanden geleden ★ 761
42 4/5 gemeten

Penetration-Testing-Study-Notes

@AnasAboreeda

Penetration Testing notes, resources and scripts

Maintainer in de EU Commit 10 maanden geleden ★ 700
41 4/5 gemeten

monkey

@guardicore

Infection Monkey - An open-source adversary emulation platform

GPL-3.0 Commit 1 jaar geleden ★ 7.096
41 5/5 gemeten

Pi.Alert

@pucherot

WIFI / LAN intruder detector. Check the devices connected and alert you with unknown devices. It also warns of the disconnection of "always connected" devices

GPL-3.0 Commit 3 jaaren geleden ★ 2.769
40 4/5 gemeten

threat-intel

@volexity

Signatures and IoCs from public Volexity blog posts.

Commit 7 dagen geleden ★ 374
40 4/5 gemeten

dnstwist

@elceef

Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation

Maintainer in de EU Commit 1 jaar geleden ★ 5.741
40 5/5 gemeten

inventory

@trickest

Asset inventory of over 800 public bug bounty programs.

MIT Commit 2 jaaren geleden ★ 1.613
40 4/5 gemeten

ScamIntelLogs

@phishdestroy

Open-source intelligence archive of crypto scam operations — internal chats, admin panels, victim records, and infrastructure data for research and investigation

Commit 15 dagen geleden ★ 445
40 4/5 gemeten

Awesome-FOFA

@FofaInfo

The FOFA Library collects usage tips, common scenarios, F&Q, and more for FOFA.

Commit 14 dagen geleden ★ 356
40 4/5 gemeten

DefenderYara

@roadwy

Extracted Yara rules from Windows Defender mpavbase and mpasbase

Commit 5 maanden geleden ★ 539
39 4/5 gemeten

Elkeid

@bytedance

Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It is derived from ByteDance's internal best practices.

Commit 5 maanden geleden ★ 2.680
39 5/5 gemeten

CyberBlue

@cyberblu3s

CyberSecurity BLUE TEAM containerized platform that brings together open-source tools for SIEM, DFIR, CTI, SOAR, and Network Analysis

Commit 5 maanden geleden ★ 548
38 4/5 gemeten

misp-training

@MISP

MISP trainings, threat intel and information sharing training materials with source code

Commit 3 maanden geleden ★ 440
38 4/5 gemeten

Sooty

@TheresAFewConors

The SOC Analysts all-in-one CLI tool to automate and speed up workflow.

GPL-3.0 Commit 2 jaaren geleden ★ 1.491
37 5/5 gemeten

phishing_catcher

@x0rz

Phishing catcher using Certstream

Maintainer in de EU Commit 2 jaaren geleden ★ 1.824
37 5/5 gemeten

ioc

@gendigitalinc

Threat Intel IoCs + bits and pieces of dark matter. Published by Gen Threat Labs.

Commit 4 maanden geleden ★ 460
36 4/5 gemeten

response

@monzo

Monzo's real-time incident response and reporting tool ⚡️

MIT Commit 3 jaaren geleden ★ 1.558
34 5/5 gemeten

shortscan

@bitquark

An IIS short filename enumeration tool

MIT Commit 2 jaaren geleden ★ 1.222
34 4/5 gemeten

Yara-Rules

@advanced-threat-research

Repository of YARA rules made by Trellix ATR Team

Apache-2.0 Commit 2 jaaren geleden ★ 629
34 4/5 gemeten

yasuo

@0xsauby

A ruby script that scans for vulnerable & exploitable 3rd-party web applications on a network

GPL-3.0 Commit 9 jaaren geleden ★ 574
34 4/5 gemeten

Bashfuscator

@Bashfuscator

A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.

MIT Commit 3 jaaren geleden ★ 2.005
34 4/5 gemeten

whids

@0xrawsec

Open Source EDR for Windows

Maintainer in de EU Commit 4 jaaren geleden ★ 1.313
34 5/5 gemeten

burpgpt

@aress31

A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan for discovering highly bespoke vulnerabilities and enables running traffic-based analysis of any type.

Apache-2.0 Commit 2 jaaren geleden ★ 2.390
33 4/5 gemeten

Pyramid

@naksyn

a tool to help operate in EDRs' blind spots

Maintainer in de EU Commit 2 jaaren geleden ★ 775
33 4/5 gemeten

dfirtrack

@dfirtrack

DFIRTrack - The Incident Response Tracking Application

Commit 9 maanden geleden ★ 539
33 4/5 gemeten

SOC-Multitool

@zdhenard42

A powerful and user-friendly browser extension that streamlines investigations for security professionals.

MIT Commit 1 jaar geleden ★ 421
33 4/5 gemeten

osquery-configuration

@palantir

A repository for using osquery for incident detection and response

Commit 1 jaar geleden ★ 904
32 4/5 gemeten

Scrummage

@matamorphosis

A Holistic OSINT and Threat Hunting Platform

GPL-3.0 Commit 2 jaaren geleden ★ 543
32 4/5 gemeten

freki

@cristianzsh

:wolf: Malware analysis platform

Zelf te hosten Commit 3 jaaren geleden ★ 445
32 4/5 gemeten

Aurora-Incident-Response

@cyb3rfox

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Apache-2.0 Commit 3 jaaren geleden ★ 1.084
31 4/5 gemeten

raven

@CycodeLabs

CI/CD Security Analyzer

Apache-2.0 Commit 2 jaaren geleden ★ 748
31 4/5 gemeten

PurpleCloud

@iknowjason

A little tool to play with Azure Identity - Azure and Entra ID lab creation tool. Blog: https://medium.com/@iknowjason/sentinel-for-purple-teaming-183b7df7a2f4

MIT Commit 2 jaaren geleden ★ 660
31 4/5 gemeten

Minimalistic-offensive-security-tools

@InfosecMatter

A repository of tools for pentesting of restricted and isolated environments.

GPL-3.0 Commit 5 jaaren geleden ★ 597
30 4/5 gemeten

Meerkat

@TonyPhipps

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

GPL-3.0 Commit 2 jaaren geleden ★ 483
30 4/5 gemeten

baitroute

@utkusen

A web honeypot library to create vulnerable-looking endpoints to detect and mislead attackers

GPL-3.0 Commit 2 jaaren geleden ★ 438
30 4/5 gemeten

ThreatActors-TTPs

@crocodyli

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving to other types of threats.

Commit 8 maanden geleden ★ 416
30 4/5 gemeten

BypassAV

@matro7sh

This map lists the essential techniques to bypass anti-virus and EDR

Commit 2 jaaren geleden ★ 3.470
30 4/5 gemeten

pfelk

@pfelk

pfSense/OPNsense + Elastic Stack

Commit 10 maanden geleden ★ 1.222
30 5/5 gemeten

Malware-Exhibit

@alvin-tosh

🚀🚀 This is a 🎇🔥 REAL WORLD🔥 🎇 Malware Collection I have Compiled & analysed by researchers🔥 to understand more about Malware threats😈, analysis and mitigation🧐.

MIT Commit 3 jaaren geleden ★ 1.186
29 4/5 gemeten

Open-Source-Security-Guide

@mikeroyal

Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.

Commit 1 jaar geleden ★ 1.111
29 4/5 gemeten

TelemetrySourcerer

@jthuraisamy

Enumerate and disable common sources of telemetry used by AV/EDR.

Apache-2.0 Commit 6 jaaren geleden ★ 864
29 4/5 gemeten

AzureHunter

@darkquasar

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

MIT Commit 4 jaaren geleden ★ 794
29 4/5 gemeten

awesome-event-ids

@stuhli

Collection of Event ID ressources useful for Digital Forensics and Incident Response

Maintainer in de EU Commit 2 jaaren geleden ★ 665
29 4/5 gemeten

privatezilla

@builtbybel

👀👮🐢🔥Performs a privacy & security check of Windows 10

MIT Commit 3 jaaren geleden ★ 3.738
29 5/5 gemeten

pacbot

@tmobile

PacBot (Policy as Code Bot)

Apache-2.0 Commit 4 jaaren geleden ★ 1.311
29 5/5 gemeten

pycharm-security

@tonybaloney

Finds security holes in your Python projects from PyCharm and GitHub

MIT Commit 1 jaar geleden ★ 353
29 5/5 gemeten

beagle

@yampelo

Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.

MIT Commit 4 jaaren geleden ★ 1.355
28 5/5 gemeten

iocextract

@pedramamini

Defanged Indicator of Compromise (IOC) Extractor.

GPL-2.0 Commit 2 jaaren geleden ★ 584
28 4/5 gemeten

incidental

@incidentalhq

An opensource incident management platform integrating with Slack.

MIT Commit 2 jaaren geleden ★ 562
28 4/5 gemeten

MIDAS

@Stream-AD

Anomaly Detection on Dynamic (time-evolving) Graphs in Real-time and Streaming manner. Detecting intrusions (DoS and DDoS attacks), frauds, fake rating anomalies.

Apache-2.0 Commit 3 jaaren geleden ★ 777
27 4/5 gemeten

atc-react

@atc-project

A knowledge base of actionable Incident Response techniques

Apache-2.0 Commit 4 jaaren geleden ★ 667
27 4/5 gemeten

DripLoader

@xuanxuan0

Evasive shellcode loader for bypassing event-based injection detection (PoC)

MIT Commit 5 jaaren geleden ★ 836
27 4/5 gemeten

psad

@mrash

psad: Intrusion Detection and Log Analysis with iptables

GPL-2.0 Commit 3 jaaren geleden ★ 428
27 4/5 gemeten

nosqli

@Charlie-belmer

NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.

AGPL-3.0 Commit 5 jaaren geleden ★ 416
27 4/5 gemeten

RmEye

@RoomaSec

戎码之眼是一个window上的基于att&ck模型的威胁监控工具.有效检测常见的未知威胁与已知威胁.防守方的利剑

Apache-2.0 Commit 3 jaaren geleden ★ 532
25 4/5 gemeten

theo

@cleanunicorn

Ethereum recon and exploitation tool.

Maintainer in de EU Commit 2 jaaren geleden ★ 349
25 5/5 gemeten

investigations

@AmnestyTech

Indicators of Compromise from Amnesty International's cyber investigations

Commit 2 jaaren geleden ★ 1.708
25 4/5 gemeten

PersistenceSniper

@last-byte

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made with ❤️ by @last0x00 and @dottor_morte

Commit 2 jaaren geleden ★ 2.142
24 4/5 gemeten

Hawkeye

@mir1ce

Windows应急响应工具---Hawkeye(鹰眼)。集Windows日志分析,进程扫描,主机信息于一体的综合应急响应分析工具

Commit 1 jaar geleden ★ 710
24 4/5 gemeten

URLextractor

@eschultze

Information gathering & website reconnaissance | https://phishstats.info/

MIT Commit 7 jaaren geleden ★ 454
23 4/5 gemeten