advancedeng's Stars
stamparm/maltrail
Malicious traffic detection system
MISP/MISP
MISP (core software) - Open Source Threat Intelligence and Sharing Platform
dalibo/pg_activity
pg_activity is a top like application for PostgreSQL server activity monitoring.
certsocietegenerale/FIR
Fast Incident Response
ssllabs/ssllabs-scan
A command-line reference-implementation client for SSL Labs APIs, designed for automated and/or bulk testing.
weppos/whois
An intelligent — pure Ruby — WHOIS client and parser.
gregs1104/pgtune
PostgreSQL configuration wizard
certtools/intelmq
IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.
OpenSOC/opensoc
OpenSOC Apache Hadoop Code
mandiant/iocs
FireEye Publicly Shared Indicators of Compromise (IOCs)
brad-sp/cuckoo-modified
Modified edition of cuckoo
xiaozhouwang/kaggle_Microsoft_Malware
code for kaggle competition Microsoft malware classification
sandialabs/scot
Sandia Cyber Omni Tracker (SCOT)
sneakerhax/PyPhisher
Python tool for phishing
MITRECND/WhoDat
Pivotable Reverse WhoIs / PDNS Fusion with Registrant Tracking & Alerting plus API for automated queries (JSON/CSV/TXT)
Malshare/MalShare-Toolkit
Set of tools for interacting with Malshare
endgameinc/binarypig
Scalable Binary Data Extraction in Hadoop
fox-it/cryptophp
CryptoPHP Indicators of Compromise
chadillac/mdns_recon
Multicast DNS and DNS service discovery daemons deployed on various systems across the Internet are misconfigured and reply to queries targeting their unicast addresses, including requests from their WAN interface. These daemons could be leveraged by attackers for sensitive information disclosure and potentially used in DDoS campaigns for reflection and in some cases amplification. This vulnerability was made public in cordination with CERT (http://www.kb.cert.org/vuls/id/550620)
Masood-M/yalih
YALIH (Yet Another Low Interaction Honeyclient) is a low Interaction Client honeypot designed to detect malicious websites through signature, anomaly and pattern matching techniques
daverstephens/The-SOC-Shop
Repository of scripts/tools that may be useful in Security Operations Centres (SOC)
blackhole-em/cuckoo2STIX
mjdorma/yara-ctypes
A Python ctypes package for libyara
GOVCERT-LU/ce1sus
ARCHIVED ce1sus, a threat information database ARCHIVED
0xd34db33f/maltego-transforms
Public Maltego Transforms
ops-trust/portal
Ops-Trust Platform - Portal
espenfjo/FjoSpidie
FjoSpidie Honey Client
iSIGHTPartners/macaroni_extension
A browser extension that seamlessly integrates your yara match notifications into VirusTotal Intelligence.
bryannolen/DFIR-PUBLIC
jackcr/yara-memory
Yara rules to be used in memory analysis