Cybersecurity and Infrastructure Security Agency
Commit today, secure tomorrow.
United States of America
Pinned Repositories
cset
Cybersecurity Evaluation Tool
decider
A web application that assists network defenders, analysts, and researchers in the process of mapping adversary behaviors to the MITRE ATT&CK® framework.
development-guide
A set of guidelines and best practices for an awesome engineering team
LME
Logging Made Easy (LME) is a no cost, open source platform that centralizes log collection, enhances threat detection, and enables real-time alerting, helping small to medium-sized organizations secure their infrastructure. LME Docs can be found at https://cisagov.github.io/lme-docs/docs/
log4j-scanner
log4j-scanner is a project derived from other members of the open-source community by CISA to help organizations identify potentially vulnerable web services affected by the log4j vulnerabilities.
Malcolm
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
manage.get.gov
A Django-based domain name registrar that interfaces with an EPP registry
RedEye
RedEye is a visual analytic tool supporting Red & Blue Team operations
ScubaGear
Automation to assess the state of your M365 tenant against CISA's baselines
Sparrow
Sparrow.ps1 was created by CISA's Cloud Forensics team to help detect possible compromised accounts and applications in the Azure/m365 environment.
Cybersecurity and Infrastructure Security Agency's Repositories
cisagov/ScubaGear
Automation to assess the state of your M365 tenant against CISA's baselines
cisagov/cset
Cybersecurity Evaluation Tool
cisagov/LME
Logging Made Easy (LME) is a no cost, open source platform that centralizes log collection, enhances threat detection, and enables real-time alerting, helping small to medium-sized organizations secure their infrastructure. LME Docs can be found at https://cisagov.github.io/lme-docs/docs/
cisagov/thorium
A scalable file analysis and data generation platform that allows users to easily orchestrate arbitrary docker/vm/shell tools at scale.
cisagov/vulnrichment
A repo to conduct vulnerability enrichment.
cisagov/dotgov-data
Official list of .gov domains
cisagov/ScubaGoggles
SCuBA Secure Configuration Baselines and assessment tool for Google Workspace
cisagov/manage.get.gov
A Django-based domain name registrar that interfaces with an EPP registry
cisagov/cyhy_amis
AWS infrastructure for Cyber Hygiene and BOD 18-01 scanning
cisagov/XFD
CyHy Dashboard
cisagov/admiral
Distributed certificate transparency log harvester
cisagov/cyhy-core
Core code for Cyber Hygiene (CyHy)
cisagov/skeleton-packer
A skeleton project for quickly getting a new cisagov packer project started.
cisagov/ansible-role-guacamole
An Ansible role for installing cisagov/guacamole-composition
cisagov/guacscanner
Scan for EC2 instances added (removed) from a VPC and create (destroy) the corresponding Guacamole connections.
cisagov/ansible-role-cyhy-reports
An Ansible role for installing cisagov/cyhy-reports.
cisagov/ansible-role-ncats-webd
An Ansible role for installing cisagov/ncats-webd.
cisagov/skeleton-ansible-role-with-test-user
A skeleton project for quickly getting a new cisagov Ansible role started when that role requires an AWS test user.
cisagov/publish-egress-ip-lambda
A Lambda function that scans a set of AWS accounts and publishes file(s) (to an S3 bucket) containing the public IP addresses of EC2 instances or Elastic IPs that have been properly tagged
cisagov/code-gov-update
Update the DHS code.gov JSON
cisagov/cool-sharedservices-cdm
Terraform code to create a site-to-site VPN tunnel between the COOL and the CISA CDM (Continuous Diagnostics and Mitigation) environment, as well as some related resources to feed COOL logging data to CDM.
cisagov/skeleton-tf-module
A skeleton project for quickly getting a new cisagov Terraform module started.
cisagov/aws-lambda-with-cloudwatch-trigger-tf-module
cisagov/cyhy-account
cisagov/cyhy-nvdsync-lambda-terraform
cisagov/cyhy-tf-root
Terraform code to deploy a Cyber Hygiene (CyHy) environment in AWS
cisagov/lme-docs
New Landing page for all documentation around CISA's Logging Made Easy project
cisagov/mongo-db-from-config
Simple library to instantiate a MongoDB database connection based on the data in a YAML configuration file
cisagov/skeleton-tf-root-module
cisagov/ansible-role-valkey-cli