Field reference for BTL1 and Tier 1 SOC work — grep-ready cheatsheets, SPL queries, Volatility workflows, live response commands
-
Updated
Mar 16, 2026 - HTML
Field reference for BTL1 and Tier 1 SOC work — grep-ready cheatsheets, SPL queries, Volatility workflows, live response commands
EyeSpy is a PowerShell tool for finding IP Cameras and spraying credentials at the underlying RTSP streams if present.
Curated cyber security resources for blue team, red team, DFIR, OSINT, AppSec, cloud security, security logging, and training.
Algorithm identification tool on hashes
Powerful Kernel Malware Investigation Platform | Software Analysis & Threat Hunting
Hackers Cookbook - Tons of hacker cli recipes ready to search and use when you need them
an open, self-hosted framework for discovering, collecting, understanding, correlating, transforming, and acting on information from heterogeneous environments.
Enter Morpheus, your advanced IOC detection tool. Powered by expert YARA rules and integrated with VirusTotal, it scans and identifies Indicators of Compromise with unmatched precision across diverse formats, redefining cybersecurity defense.
A curation of tools presented at DEF CON conference each year, the world's largest hacker con.
用Go编写的轻量文件监控器. 可以监控终端上指定文件夹内的变化, 阻止删除,修改,新增操作. 可以用于AWD比赛或者终端应急响应
.NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on disk binaries.
The AI Autonomous SOC & Purple-Team Engine
Automated IP blacklist aggregator from 23 threat intelligence sources - updated hourly via GitHub Actions
BasicEventViewer4 (BEV v4.0), this code will useful for All Blue/Purple Teams , RealTime Monitoring Sysmon Events , Mitre Attack Detections via yaml files
A runtime Assembly dumper for powershell to combat the rise in .net based crypters and malware.
Verified Entity Identity Lock (Expose hidden trust paths in your AWS IAM setup before they become security risks.)
ICS Incident Response Automation Framework Python framework for executing automated incident response playbooks in ICS/SCADA environments. Supports network isolation, forensic preservation, logic restoration, and safety system interventions. Designed for defenders, researchers, and red team simulations in operational technology networks.
This Black Python script is not a game! It is a powerful tool to monitor the traffic between clients and malicious .onion sites. We use a code like this to capture bad actors
Plateforme OSINT défensive pour surveiller le dark web : crawl .onion via Tor, détection de fuites de données, alertes ransomware/exploits, extraction d'entités. Stack : Python + PostgreSQL + Elasticsearch + Redis. Docker Compose ready.
Correlating kernel notifications with the lack of ETW events to detect ETW Patching
To associate your repository with the blue-team-tool topic, visit your repo's landing page and select "manage topics."