APT Emulation tool to exfiltrate sensitive .docx, .pptx, .xlsx, .pdf files
-
Updated
Apr 2, 2025 - C++
APT Emulation tool to exfiltrate sensitive .docx, .pptx, .xlsx, .pdf files
A Python script that automates static analysis, yara analysis and reverse-engineering on Windows (exe, sys, dll) binaries!
Digital forensics simulator for training CERT and DFIR analysts!
A script that webs scrapes multiple webpages for known vulnerable Windows Drivers, SHA256 hashes all system drivers, looks for matching driver names and SHA256 hashes.
A script to that checks for active connections to known malicious foreign IP addresses.
PyCanary: CMD line tool to monitor any directory for file access or file changes, log event, send basic alert to user, and dump and process information collected. There is also a background thread monitoring all created processes and logging them for later analysis.
A just honeypot. Simulates 12+ network services (SSH, HTTP, DNS, Modbus, Redis), captures credentials in real time, maps attacker behavior to MITRE ATT&CK, and visualizes everything on a live dashboard. Not production-grade — a transparent, MVP, hackable base for learning attack patterns.
A set of blue team scripts for hardening Linux systems focusing on competitions and locking a system down.
APT Emulation tool to exfiltrate sensitive .docx, .pptx, .xlsx, .pdf files
Python-based tool that uses kismet to perform passive wireless reconnaissance
Basic rapid linux IR bash script
This tool is designed to scan log files for various security events and present the findings in an easy-to-read table format directly in your terminal. It includes features for custom pattern detection and provides recommended remedies for detected issues.
An internet monitor tool for cyber-security. (Imported from VisAwesme to NetKnights)
Simple html pages to export / backup and restore Cyberchef Recipes from local installation.
Scripts to run at a Cybersecurity Blue-Team competition during the 5 minutes before Red Team attacks
Lightweight SOC platform for security event monitoring, detection engineering, alert triage, MITRE ATT&CK mapping, and incident response.
LogGuardian is a Blue Team, log and config analyzer tool designed to help detect brute force attacks, misconfigurations, and other security events in real-time.
To associate your repository with the blueteaming-tools topic, visit your repo's landing page and select "manage topics."