![](/assets/headers/header-logo.png)

![](https://img.shields.io/badge/Tools%20%26%20Resources%20Available-20-757575?style=for-the-badge)

### Active Directory

* [LogonTracer](https://github.com/JPCERTCC/LogonTracer) - Investigate malicious Windows logon by visualizing and analyzing Windows event log. ![last-commit](https://img.shields.io/github/last-commit/JPCERTCC/LogonTracer?style=flat)

### Data Loss Prevention (DLP)

* [LOTS Project](https://lots-project.com/#) - Attackers are using popular legitimate domains when conducting phishing, C&C, exfiltration and downloading tools to evade detection. This project provides domains to monitor.

### Management Platform

* [DFIRTrack](https://github.com/dfirtrack/dfirtrack) - The Incident Response Tracking Application. ![last-commit](https://img.shields.io/github/last-commit/dfirtrack/dfirtrack?style=flat)
* [FIR](https://github.com/certsocietegenerale/FIR) - Fast Incident Response allows for easy creation, tracking, and reporting of cybersecurity incidents. ![last-commit](https://img.shields.io/github/last-commit/certsocietegenerale/FIR?style=flat)
* [The Hive](https://github.com/TheHive-Project/TheHive) - A Scalable, Open Source and Free Security Incident Response Platform. ![last-commit](https://img.shields.io/github/last-commit/TheHive-Project/TheHive?style=flat)
* [Wazuh](https://github.com/wazuh/wazuh) - Capable of protecting workloads across on-premises, virtualized, containerized, and cloud-based environments. ![last-commit](https://img.shields.io/github/last-commit/wazuh/wazuh?style=flat)

### Reporting

* [Cortex](https://github.com/TheHive-Project/Cortex) - Powerful Observable Analysis and Active Response Engine. ![last-commit](https://img.shields.io/github/last-commit/TheHive-Project/Cortex?style=flat)
* [ETWMonitor](https://github.com/Processus-Thief/ETWMonitor) -  Windows notifier tool that detects suspicious connections by monitoring ETW event logs. ![last-commit](https://img.shields.io/github/last-commit/Processus-Thief/ETWMonitor?style=flat)
* [Log-MD](https://www.imfsecurity.com/why-log-md) -Tool to assist Information Security and IT Professionals discover the artifacts needed to understand if a Windows system has a malware infection.  
* [Response](https://github.com/monzo/response) - Real-time incident response and reporting tool. ![last-commit](https://img.shields.io/github/last-commit/monzo/response?style=flat)
* [Velociraptor](https://github.com/Velocidex/velociraptor) - A tool for collecting host based state information using Velocidex Query Language (VQL) queries. ![last-commit](https://img.shields.io/github/last-commit/Velocidex/velociraptor?style=flat)

---

## Indicators of Compromise

### Frameworks

* [IoCextract](https://github.com/InQuest/iocextract) -  Defanged Indicator of Compromise (IOC) Extractor. ![last-commit](https://img.shields.io/github/last-commit/InQuest/iocextract?style=flat)

### Lists

* [Log4Shell](https://github.com/curated-intel/Log4Shell-IOCs) - Simple IOC and YARA scanner. ![last-commit](https://img.shields.io/github/last-commit/curated-intel/Log4Shell-IOCs?style=flat)

### Scanners

* [Fenrir](https://github.com/Neo23x0/Fenrir) - Simple Bash IOC Scanner. ![last-commit](https://img.shields.io/github/last-commit/Neo23x0/Fenrir?style=flat)
* [IoC Radar](https://socradar.io/labs/ioc-radar/) - The IOC Radar service provides you with IoCs about threat actors, malware and attackers.
* [Loki](https://github.com/Neo23x0/Loki) - Simple IOC and YARA scanner. ![last-commit](https://img.shields.io/github/last-commit/Neo23x0/Loki?style=flat)
* [PersistenceSniper](https://github.com/last-byte/PersistenceSniper/) - Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. ![last-commit](https://img.shields.io/github/last-commit/last-byte/PersistenceSniper?style=flat)
* [Redline](https://www.fireeye.com/services/freeware/redline.html) - FireEye's free endpoint security tool, provides host investigative capabilities.
* [Thor Lite](https://www.nextron-systems.com/thor-lite/) - Free IOC and YARA Scanner.

### YARA

* [yarGen](https://github.com/Neo23x0/yarGen) - yarGen is a generator for YARA rules. ![last-commit](https://img.shields.io/github/last-commit/Neo23x0/yarGen?style=flat)
