Pinned Repositories
osquery-defense-kit
Production-ready detection & response queries for osquery
slowjam
SlowJam: latency profiler for Go programs
triage-party
🎉 Triage Party: massively multi-player GitHub triage 🎉
minikube
Run Kubernetes locally
cstat
A more civilized iostat for measuring system business
quietude
Quietude removes distractions from your Android phone (DIY Lightphone)
sigstore-the-local-way
sigstore installation walkthrough, local
sunlight
Linux #rootkit and #malware revealer
time-to-k8s
Local Kubernetes Benchmark
ttp-bench
Adversary emulation for EDR/SIEM testing (macOS/Linux)
tstromberg's Repositories
tstromberg/sigstore-the-local-way
sigstore installation walkthrough, local
tstromberg/ttp-bench
Adversary emulation for EDR/SIEM testing (macOS/Linux)
tstromberg/quietude
Quietude removes distractions from your Android phone (DIY Lightphone)
tstromberg/sunlight
Linux #rootkit and #malware revealer
tstromberg/bincapz
extract capabilities out of binaries
tstromberg/malware-menagerie
Malware samples for POSIX platforms (macOS, Linux, etc.)
tstromberg/roho
A new Go-language client library for accessing the Robinhood API.
tstromberg/bincapz-samples
Samples used for developing and testing bincapz rules.
tstromberg/bodyfile
A bodyfile parsing library
tstromberg/capa-rules
Standard collection of rules for capa: the tool for enumerating the capabilities of programs
tstromberg/digestabot
Github Action to automatically update digests for container images.
tstromberg/docker-forensics
Tools to assist in forensicating docker
tstromberg/dot.files
My dot.files.
tstromberg/edu
Educational Resources for Software Supply Chain Security
tstromberg/FSEventsParser
Parser for macOS/iOS FSEvents Logs (Python 3)
tstromberg/github-audit-alerter
Slack alert bot for matching Github Audit Events
tstromberg/hCrypto
FREE CRYPTO CHECKER
tstromberg/images
Public Chainguard Images
tstromberg/kolide-pipeline-bot
Generate Slack notifications from Kolide pipelines
tstromberg/kolide-timeline
Turn Kolide pipeline logs into a timeline
tstromberg/kosamlide
just a SAML experiment
tstromberg/launcher
Osquery launcher, autoupdater, and packager
tstromberg/os
Main package repository for production Wolfi images
tstromberg/osqtool
Automated generation & manipulation of #osquery packs
tstromberg/osquery-defense-kit
Production-ready detection & response queries for osquery
tstromberg/secureframe-issue-sync
Sync Secureframe tests to GitHub issues (unofficial)
tstromberg/shellack
portable shell implant PoC
tstromberg/timeliner
A rewrite of mactime, a bodyfile reader
tstromberg/wolfictl
A CLI used to work with the Wolfi OSS project
tstromberg/yacls
Collect ACLs from SaaS platforms for periodic user access reviews