Skip to content
View s-Fl's full-sized avatar

Block or report s-Fl

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

🛡️ Blue team services

42 repositories

Collaborative forensic timeline analysis

Python 3,265 642 Updated Feb 13, 2026

A toolset to make a system look as if it was the victim of an APT attack

Batchfile 2,710 456 Updated Sep 23, 2025

ReversingLabs YARA Rules

YARA 893 116 Updated Nov 3, 2025

Investigate malicious Windows logon by visualizing and analyzing Windows event log

Python 3,120 483 Updated Oct 19, 2025

TrustedSec Sysinternals Sysmon Community Guide

Python 1,365 182 Updated Feb 10, 2026

A resource containing all the tools each ransomware gangs uses

1,327 151 Updated Dec 24, 2025

Repository documenting how Threat Intelligence and / or a Threat Intelligence Platform can prove its value to an organisation.

53 4 Updated Oct 23, 2024

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

Java 3,599 712 Updated Feb 12, 2026

Distributed malware processing framework based on Python, Redis and S3.

Python 460 50 Updated Dec 1, 2025

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

Python 780 110 Updated Feb 13, 2026

Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections…

Shell 4,395 622 Updated Feb 14, 2026

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

Shell 7,194 1,129 Updated Feb 13, 2026

A framework for orchestrating forensic collection, processing and data export

Python 341 76 Updated Feb 13, 2026

Sandbox for automated Linux malware analysis.

Python 484 95 Updated May 1, 2023

A repository of curated datasets from various attacks

Python 727 132 Updated Feb 6, 2026

Fast Incident Response

JavaScript 1,989 514 Updated Feb 10, 2026

KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.

Python 1,633 315 Updated Feb 11, 2026

Digital Forensics Investigation Platform

JavaScript 872 120 Updated Oct 12, 2024

Automated YARA Rule Standardization and Quality Assurance Tool

Python 282 35 Updated Feb 8, 2026

Taranis AI is an advanced Open-Source Intelligence (OSINT) tool, leveraging Artificial Intelligence to revolutionize information gathering and situational analysis.

Python 926 112 Updated Feb 13, 2026

A secure sandbox environment for malware developers and red teamers to test payloads against detection mechanisms before deployment. Integrates with LLM agents via MCP for enhanced analysis capabil…

YARA 1,303 147 Updated Nov 12, 2025

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

C 7,304 1,134 Updated Feb 13, 2026

Fast C++ logging library.

C++ 28,334 5,040 Updated Feb 9, 2026

✨ A curated list of awesome threat detection and hunting resources 🕵️‍♂️

4,499 729 Updated Jan 5, 2026

Useful resources for SOC Analyst and SOC Analyst candidates.

886 154 Updated Aug 28, 2023

Helm charts for running open source digital forensic tools in Kubernetes

Go Template 182 21 Updated Feb 12, 2026

Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.

Shell 15,253 1,575 Updated Jan 28, 2026