#blue-team (12 Repositories)
Ranked open-source repositories tagged with #blue-team, scored by pull request acceptance likelihood and maintainer engagement velocity.
30.9%
2.9h
12 repositories tagged #blue-team
Karib0u/rustinel
Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.
BlessedRebuS/Krawl
Krawl is a customizable, lightweight, cloud-native web deception server and anti-crawler that creates fake web applications with low-hanging vulnerabilities using realistic, randomly generated decoy data and AI-generated HTML templates.
BARGHEST-ngo/MESH
Wireless ADB, over the internet; not just local Wi-Fi. An encrypted, censorship-resistant mesh VPN making remote forensics and network monitoring seamless.
Pnwcomputers/ULTIMATE-CYBERSECURITY-MASTER-GUIDE
This repository provides a centralized resource for operational cyber defense and offense, compiling Theory, Tools, Operating Procedures, and Step-by-Step Guides across various critical security domains. Content is sourced from industry-leading books and technical presentations, focusing on practical application rather than JUST theory.
Bashfuscator/Bashfuscator
A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.
helixmap/sigwood
Local-first, transparent threat hunting for the logs you already have: Zeek, Pi-hole, syslog, CloudTrail. Named technique behind every finding. No SIEM, no agent, no black box.
PaperMtn/slack-watchman
Slack enumeration and exposed secrets detection tool
awslabs/aws-cloudsaga
AWS CloudSaga - Simulate security events in AWS
codeexpress/respounder
Respounder detects presence of responder in the network.
joeavanzato/Trawler
PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.
xsa/infosec-events
List of past and future infosec related events.
benscha/KQLAdvancedHunting
Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MITRE ATT&CK mapping.