Security Operations
Browse 381 cybersecurity tools tagged with "Security Operations" (showing 250)

Logsign Unified SO
Threat Hunting
Logsign Unified SO Platform on SecurityListing: SOAR platform automating threat detection, incident response, and workflows

Reverse Engineering Challenges
Cyber Range Training
Reverse Engineering Challenges on SecurityListing: A collection of reverse engineering challenges covering a wide range of topics and difficulty levels.

CBRX
Digital Forensics and Incident Response
CBRX on SecurityListing: CBRX is a cloud-based platform that automates incident analysis and reporting for cybersecurity teams.

ProLion CryptoSpike
Extended Detection and Response
ProLion CryptoSpike on SecurityListing: Real-time ransomware detection & blocking for storage systems with recovery

Damn Vulnerable iOS
Penetration Testing
Damn Vulnerable iOS App (DVIA) on SecurityListing: iOS application for testing iOS penetration testing skills in a legal environment.

Monkey-Spider
Security Operations
Monkey-Spider on SecurityListing: A crawler-based low-interaction client honeypot for exposing website threats.

Brute Ratel C4
Offensive Security
Brute Ratel C4 on SecurityListing: Advanced command and control tool for red teaming and adversary simulation with extensive features and evasion capabilities.

PEview
Digital Forensics and Incident Response
PEview on SecurityListing: A PE/COFF file viewer that displays header, section, directory, import table, export table, and resource information within various file types.

Cipher xMDR
Threat Hunting
Cipher xMDR on SecurityListing: AI-driven MDR service providing unified threat detection across IT, OT, cloud

Anvilogic
Security Information and Event Management
Anvilogic on SecurityListing: Anvilogic is a SIEM platform that streamlines detection engineering, offers cost-effective data management, and enhances threat detection capabilities.

Nomoreransom
Digital Forensics and Incident Response
Nomoreransom on SecurityListing: No More Ransom is a collaborative project to combat ransomware attacks by providing decryption tools and prevention advice.

Cobalt Strike HTTP
Offensive Security
Cobalt Strike HTTP C2 Redirectors with Apache mod_rewrite on SecurityListing: Using Apache mod_rewrite as a redirector to filter C2 traffic for Cobalt Strike servers.

DorkSearch
Offensive Security
DorkSearch on SecurityListing: An AI-powered Google Dorking tool that helps create effective search queries to uncover sensitive information on the internet.

Art of Memory
Digital Forensics and Incident Response
Art of Memory Forensics on SecurityListing: A comprehensive guide to memory forensics, covering tools, techniques, and procedures for analyzing volatile memory.

Attack-Defense Online Lab
Vulnerability Assessment
Attack-Defense Online Lab on SecurityListing: Hands-on cybersecurity training and testing platform with 1800+ labs

AccessData FTK Imager
Digital Forensics and Incident Response
AccessData FTK Imager on SecurityListing: A digital forensic tool for creating forensic images of computer hard drives and analyzing digital evidence.

Dropzone AI
Security Orchestration Automation and Response
Dropzone AI on SecurityListing: Dropzone AI is an autonomous AI agent for SOCs that performs end-to-end investigations of security alerts, integrating with existing cybersecurity tools and data sources.

ESET Protect MDR
Threat Hunting
ESET Protect MDR Ultimate on SecurityListing: A managed security service providing comprehensive endpoint protection, XDR capabilities, and 24/7 managed detection and response across multiple platforms and environments.

Kali
Vulnerability Assessment
Kali on SecurityListing: Kali Linux is a specialized Linux distribution for cybersecurity professionals, focusing on penetration testing and security auditing.

Honeyd Tools
Security Operations
Honeyd Tools on SecurityListing: A collection of tools that can be used with Honeyd for data analysis or other purposes

LAMPSecurity Training
Penetration Testing
LAMPSecurity Training on SecurityListing: A series of vulnerable virtual machine images with documentation to teach Linux, Apache, PHP, MySQL security.

PentesterLab PRO
Penetration Testing
PentesterLab PRO on SecurityListing: Online platform offering 700+ hands-on web security exercises and training

Lumifi ShieldVision™
Endpoint Detection and Response
Lumifi ShieldVision™ on SecurityListing: SOAR platform with investigation, automation, and incident mgmt capabilities

DuskRise Security Dashboard
Security Information and Event Management
DuskRise Security Dashboard on SecurityListing: Security dashboard for remote network visibility and policy enforcement

LogCraft Detection Engineering
Endpoint Detection and Response
LogCraft Detection Engineering on SecurityListing: Detection-as-code platform for managing detection rules across SIEM/EDR/XDR

D3 Morpheus AI
Threat Intelligence Platforms
D3 Morpheus AI SOC on SecurityListing: AI-driven SOC platform for automated alert triage, investigation, and response

Intrusion Detection Honeypots
Network Security
Intrusion Detection Honeypots on SecurityListing: A foundational guide for using deception against computer network adversaries using honeypots to detect adversaries before they accomplish their goals.

Metadefender Cloud
Digital Forensics and Incident Response
Metadefender Cloud on SecurityListing: Advanced threat prevention and detection platform leveraging Deep CDR, Multiscanning, and Sandbox technologies to protect against data breaches and ransom attacks.

Mandiant Threat Defense
Threat Hunting
Mandiant Threat Defense on SecurityListing: Managed threat detection, hunting, and response service by Mandiant experts

xargs
Offensive Security
xargs on SecurityListing: A command that builds and executes command lines from standard input, allowing for the execution of commands with multiple arguments.

exif
Digital Forensics and Incident Response
exif on SecurityListing: A command-line utility to show and change EXIF information in JPEG files

Lab of a
Offensive Security
Lab of a Penetration Tester: Week of Evading Microsoft ATA on SecurityListing: A week-long series of articles and talks on evading Microsoft Advanced Threat Analytics (ATA) detection

Capsicum
Container Security
Capsicum on SecurityListing: A security framework for process isolation and sandboxing based on capability-based security principles.

ParrotSec
Offensive Security
ParrotSec on SecurityListing: Parrot Security OS is a comprehensive, secure, and customizable operating system for cybersecurity professionals, offering over 600+ tools and utilities for red and blue team operations.

Logz.io Distributed Tracing
Security Information and Event Management
Logz.io Distributed Tracing on SecurityListing: Distributed tracing platform for monitoring microservices performance

Logpoint SecOps Platform
Security Information and Event Management
Logpoint SecOps Platform on SecurityListing: Integrated SIEM, SOAR, NDR platform with central fleet management capabilities

Combatting Incident Responders
Offensive Security
Combatting Incident Responders with Apache mod_rewrite on SecurityListing: Using Apache mod_rewrite rules to rewrite incident responder or security appliance requests to an innocuous website or the target's real website.

Zenduty
Security Orchestration Automation and Response
Zenduty on SecurityListing: Zenduty's platform provides real-time operational health monitoring and incident response orchestration to improve incident response times and build a solid on-call culture.

Event Log Explorer
Security Information and Event Management
Event Log Explorer on SecurityListing: Event Log Explorer is a software solution for viewing, analyzing, and monitoring events recorded in Microsoft Windows event logs, offering advanced features and efficient filtering capabilities.

BeEF
Penetration Testing
BeEF on SecurityListing: BeEF is a specialized penetration testing tool for exploiting web browser vulnerabilities to assess security.

ORDR IQ
Security Orchestration Automation and Response
ORDR IQ on SecurityListing: Multi-agent AI orchestrator for IT and security workflow automation

Blockbit XDR
Threat Intelligence Platforms
Blockbit XDR on SecurityListing: XDR platform providing detection and response across endpoints, networks, and email

PoshC2
Penetration Testing
PoshC2 on SecurityListing: A proxy aware C2 framework for penetration testing, red teaming, post-exploitation, and lateral movement with modular format and highly configurable payloads.

Fabric Platform by
Security Information and Event Management
Fabric Platform by BlackStork on SecurityListing: Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.

Devo Security Data
Threat Hunting
Devo Security Data Platform on SecurityListing: Security data platform combining SIEM, SOAR, UEBA, and threat hunting

ExploitDB
Penetration Testing
ExploitDB on SecurityListing: A CVE compliant archive of public exploits and corresponding vulnerable software, and a categorized index of Internet search engine queries designed to uncover sensitive information.

Quorum Cyber Emergency
Threat Hunting
Quorum Cyber Emergency MDR on SecurityListing: Emergency MDR service for orgs experiencing active cyber incidents or attacks

FEX Imager™
Digital Forensics and Incident Response
FEX Imager™ on SecurityListing: Forensic imaging program with full hash authentication and various acquisition options.

Fraud.com fcase Fraud
API Security
Fraud.com fcase Fraud Orchestration on SecurityListing: Fraud orchestration platform for financial institutions

Fidelis Security
Endpoint Detection and Response
Fidelis Security on SecurityListing: XDR platform with NDR, EDR, deception, AD security, and CNAPP capabilities

Intelligence-Driven Incident Response
Digital Forensics and Incident Response
Intelligence-Driven Incident Response on SecurityListing: ENISA Training Resources offers online training material for cybersecurity specialists, covering technical areas such as artefact handling and analysis.

Gravwell Security Data
Threat Hunting
Gravwell Security Data Platform on SecurityListing: Security data platform for log analysis, metrics, and threat hunting

Logpoint Director
Security Information and Event Management
Logpoint Director on SecurityListing: A centralized management console for efficiently operating and monitoring large-scale, multitenant Logpoint SIEM deployments across customers, geographies, and organizational divisions.

GNU Netcat
Offensive Security
GNU Netcat on SecurityListing: A featured networking utility for reading and writing data across network connections with advanced capabilities.

Valkyrie Comodo
Digital Forensics and Incident Response
Valkyrie Comodo on SecurityListing: Valkyrie is a sophisticated file verdict system that enhances malware detection through behavioral analysis and extensive file feature examination.

Itential Orchestration
API Security
Itential Orchestration on SecurityListing: AI-powered orchestration platform for network & infrastructure automation

HoneyDrive
Security Operations
HoneyDrive on SecurityListing: HoneyDrive is the premier honeypot Linux distro with over 10 pre-installed honeypot software packages and numerous analysis tools.

Harness AI for
Security Orchestration Automation and Response
Harness AI for DevOps on SecurityListing: AI-powered DevOps platform for CI/CD, testing, security, and cost mgmt.

Jupyter Notebooks for
Threat Hunting
Jupyter Notebooks for Threat Hunting on SecurityListing: Utilize Jupyter Notebooks to enhance threat hunting capabilities by focusing on different threat categories or stages.
Detecting Lateral Movement
Digital Forensics and Incident Response
Detecting Lateral Movement through Tracking Event Logs (Version 2) on SecurityListing: A report on detecting lateral movement through tracking event logs, updated to include analysis of various tools and commands used by attackers.

Logz.io Log Management
Security Information and Event Management
Logz.io Log Management on SecurityListing: Cloud-based log management platform with AI-driven analysis and observability

GNU Binutils
Digital Forensics and Incident Response
GNU Binutils on SecurityListing: A collection of binary tools for various purposes including linking, assembling, profiling, and more.

StrangeBee Cortex
Security Orchestration Automation and Response
StrangeBee Cortex on SecurityListing: Open-source observable analysis engine and companion tool for TheHive platform

DFIR CTF: Precision
Cyber Range Training
DFIR CTF: Precision Widgets of North Dakota Intrusion on SecurityListing: A cybersecurity challenge where you play the role of an incident response consultant investigating an intrusion at Precision Widgets of North Dakota.

Covert Red Team
Offensive Security
Covert Red Team Attack Infrastructure on SecurityListing: Back-end component for red team operations with crucial design considerations.

How to Write
Offensive Security
How to Write Malleable C2 Profiles for Cobalt Strike on SecurityListing: Learn how to create new Malleable C2 profiles for Cobalt Strike to avoid detection and signatured toolset

CrowdStrike Falcon Onum
Security Information and Event Management
CrowdStrike Falcon Onum on SecurityListing: Data pipeline mgmt for SOC transformation with real-time data processing

Hunters Pathfinder AI
Threat Hunting
Hunters Pathfinder AI on SecurityListing: AI-driven SOC platform with autonomous threat detection, investigation & response

Hybrid-Analysis
Threat Intelligence Platforms
Hybrid-Analysis on SecurityListing: Falcon Sandbox is a malware analysis framework that provides in-depth static and dynamic analysis of files, offering hybrid analysis, behavior indicators, and integrations with various security tools.

ExoneraTor
Digital Forensics and Incident Response
ExoneraTor on SecurityListing: Check if an IP address was used as a Tor relay on a given date.

Bifrozt
Security Operations
Bifrozt on SecurityListing: High interaction honeypot solution for Linux systems with data control and integrity features.

Enterprise Detection &
Threat Hunting
Enterprise Detection & Response: A Simple Hunting Maturity Model on SecurityListing: A simple maturity model for enterprise detection and response

Aircrack-ng
Offensive Security
Aircrack-ng on SecurityListing: A complete suite of tools for assessing WiFi network security with capabilities for monitoring, attacking, testing, and cracking.

Agentic AI AR2™
Threat Intelligence Platforms
Agentic AI AR2™ on SecurityListing: Autonomous AI SOC platform for automated threat response and remediation

Graylog AI-Powered Security
API Security
Graylog AI-Powered Security & IT Operations on SecurityListing: AI-powered SIEM, API security, and log management platform

Zeronsec Anrita
Threat Hunting
Zeronsec Anrita on SecurityListing: Real-time threat detection and monitoring platform with SIEM capabilities

Huntbase Platform
Threat Hunting
Huntbase Platform on SecurityListing: Platform for threat investigation with automation and knowledge management

Logpoint SOAR &
Security Orchestration Automation and Response
Logpoint SOAR & Automation on SecurityListing: SOAR platform for automated alert triage, investigation, and response

NSFOCUS Intelligent Security
Threat Hunting
NSFOCUS Intelligent Security Operations Platform on SecurityListing: XDR platform with SOAR capabilities for security operations centers

Panaseer Metrics Measurement
Risk Assessment
Panaseer Metrics Measurement on SecurityListing: Automates security metrics measurement and reporting for posture management.

Reversing and Exploiting
Offensive Security
Reversing and Exploiting ARM Binaries: rwthCTF Trafman on SecurityListing: A tutorial on setting up a virtual ARM environment, reversing ARM binaries, and writing basic exploits for ARM using the trafman challenge of rwthCTF as an example.

DNS Tunnelling
Offensive Security
DNS Tunnelling on SecurityListing: A technique to encode data within DNS queries for covert communication channels.

Grafana Cloud Logs
Security Information and Event Management
Grafana Cloud Logs on SecurityListing: Managed log aggregation system for storing and querying application logs

RAD Security RAD
Security Orchestration Automation and Response
RAD Security RAD FusionAI Core on SecurityListing: AI-powered security platform that correlates signals & automates actions

IonX Verisys FIM
Security Information and Event Management
IonX Verisys FIM on SecurityListing: File integrity monitoring for Windows, Linux & network devices

BitLyft AIR®
Security Orchestration Automation and Response
BitLyft AIR® on SecurityListing: Automated incident response platform for Microsoft 365 and identity systems

Perisai Agentic-AI Hyperautomation
Endpoint Detection and Response
Perisai Agentic-AI Hyperautomation on SecurityListing: AI-driven SOAR platform for automated incident response & threat detection

Binalyze AIR
Digital Forensics and Incident Response
Binalyze AIR on SecurityListing: Modern digital forensics and incident response platform with comprehensive tools.

cabextract
Digital Forensics and Incident Response
cabextract on SecurityListing: Free software for extracting Microsoft cabinet files, supporting all features and formats of Microsoft cabinet files and Windows CE installation files.

MFTECmd
Digital Forensics and Incident Response
MFTECmd on SecurityListing: A command-line tool for managing and analyzing Microsoft Forefront TMG and UAG configurations.

GHH - Google
Security Operations
GHH - Google Hack Honeypot on SecurityListing: GHH is a honeypot tool to defend against search engine hackers using Google as a hacking tool.

Logsign USO Platform
Security Information and Event Management
Logsign USO Platform on SecurityListing: SIEM platform with compliance reporting for regulatory standards

Graylog
Security Information and Event Management
Graylog on SecurityListing: Graylog offers advanced log management and SIEM capabilities to enhance security and compliance across various industries.

Grep App
Threat Hunting
Grep App on SecurityListing: Search engine for open-source Git repositories with advanced features like case sensitivity and regular expressions.

DiskShadow
Offensive Security
DiskShadow on SecurityListing: A tool that exposes the functionality of the Volume Shadow Copy Service (VSS) for creation, enumeration, and manipulation of volume shadow copies, with features for persistence and evasion.

DVWA - Brute
Offensive Security
DVWA - Brute Force (High Level) - Anti-CSRF Tokens on SecurityListing: A guide to brute forcing DVWA on the high security level with anti-CSRF tokens

Alien Vault Ossim
Vulnerability Assessment
Alien Vault Ossim on SecurityListing: AlienVault OSSIM provides an all-in-one security management solution with asset discovery, vulnerability assessment, and SIEM capabilities.

Belkasoft Evidence Center
Digital Forensics and Incident Response
Belkasoft Evidence Center on SecurityListing: Comprehensive digital forensics and incident response platform for law enforcement, corporate, and academic institutions.

Ophcrack
Offensive Security
Ophcrack on SecurityListing: Ophcrack is a free Windows password cracker based on rainbow tables with various features for password recovery.

Impost
Network Security
Impost on SecurityListing: Impost is a powerful network security auditing tool with honey pot and packet sniffer capabilities.

KFSensor
Penetration Testing
KFSensor on SecurityListing: KFSensor is an advanced Windows honeypot system for detecting hackers and worms by simulating vulnerable system services.

PhotoRec
Digital Forensics and Incident Response
PhotoRec on SecurityListing: A free, open-source file data recovery software that can recover lost files from hard disks, CD-ROMs, and digital camera memory.

Lumifi Network Detection
Managed Detection and Response
Lumifi Network Detection & Response (NDR) on SecurityListing: Managed NDR service monitoring network traffic for threats via co-managed model

Abusing DCOM For
Offensive Security
Abusing DCOM For Yet Another Lateral Movement Technique on SecurityListing: An exploration of a new method to abuse DCOM for remote payload execution and lateral movement.

LogRythm SIEM
Security Information and Event Management
LogRythm SIEM on SecurityListing: LogRhythm SIEM is a comprehensive security information and event management platform that collects, analyzes, and responds to security events across an organization's IT infrastructure.

Verisys File Integirty
Security Information and Event Management
Verisys File Integirty Monitoring on SecurityListing: A next-generation file integrity monitoring and change detection system

Abusing the COM
Offensive Security
Abusing the COM Registry Structure: CLSID, LocalServer32, & InprocServer32 on SecurityListing: Abusing the COM Registry Structure: CLSID, LocalServer32, & InprocServer32

Magnet ACQUIRE
Digital Forensics and Incident Response
Magnet ACQUIRE on SecurityListing: Magnet ACQUIRE offers robust data extraction capabilities for digital forensics investigations, supporting a wide range of devices.

NetWitness Cybersecurity
Endpoint Detection and Response
NetWitness Cybersecurity on SecurityListing: Integrated XDR platform combining NDR, SIEM, EDR, and SOAR capabilities

Threat.Zone
Digital Forensics and Incident Response
Threat.Zone on SecurityListing: Holistic malware analysis platform with interactive sandbox, static analyzer, and emulation capabilities.

State of Security
Offensive Security
State of Security on SecurityListing: Sysreptor offers a customizable security reporting solution for penetration testers and red teamers.

detections.ai Detections
Threat Intelligence Platforms
detections.ai Detections on SecurityListing: Community platform for sharing and creating detection rules with AI

Purple Academy by
Cyber Range Training
Purple Academy by Picus on SecurityListing: Platform offering cybersecurity courses for Red, Blue, and Purple Teamers by Picus.

BitLyft True MDR
Threat Hunting
BitLyft True MDR on SecurityListing: 24/7 managed detection and response service with US-based SOC analysts

H3C U-Center Unified
Security Information and Event Management
H3C U-Center Unified O&M Cloud on SecurityListing: Unified O&M cloud platform for network and IT infrastructure management

hackxor
Cyber Range Training
hackxor on SecurityListing: A platform offering hacking missions to test and enhance skills.

Quorum Cyber Clarity
Data Loss Prevention
Quorum Cyber Clarity on SecurityListing: Managed security services platform offering MDR, threat detection, and DLP

Threatpost
Offensive Security
Threatpost on SecurityListing: Sysreptor offers a customizable reporting solution for penetration testing and red teaming.

Userland API Monitoring
Digital Forensics and Incident Response
Userland API Monitoring and Code Injection Detection on SecurityListing: Explores malware interaction with Windows API and methods for detection and prevention.

Cydarm Platform
Security Orchestration Automation and Response
Cydarm Platform on SecurityListing: SOC management platform for incident response and cyber response management

Shuffler
Security Orchestration Automation and Response
Shuffler on SecurityListing: Shuffle Automation provides an open-source platform for security orchestration, automation, and response.

PAGO Networks PAGO
Endpoint Detection and Response
PAGO Networks PAGO MDR on SecurityListing: MDR service with real-time monitoring and threat response capabilities

Explorer Suite
Digital Forensics and Incident Response
Explorer Suite on SecurityListing: A freeware suite of tools for PE editing and process viewing, including CFF Explorer and Resource Editor.

Cobalt Strike's ExternalC2
Penetration Testing
Cobalt Strike's ExternalC2 framework on SecurityListing: A specification/framework for extending default C2 communication channels in Cobalt Strike

Daylight Threat Detection
Threat Hunting
Daylight Threat Detection and Response on SecurityListing: AI-powered MDR combining agentic AI with human expertise for threat detection

HoneyDB
Threat Hunting
HoneyDB on SecurityListing: HoneyDB is a honeypot-based threat intelligence platform that provides real-time insights into attacker behavior and malicious activity on networks.

Attic MDR
Threat Hunting
Attic MDR on SecurityListing: 24/7 managed detection and response service for Microsoft 365 environments

Lumifi Managed Detection
Endpoint Detection and Response
Lumifi Managed Detection & Response on SecurityListing: 24/7 MDR service with automated threat hunting and response capabilities

Bait and Switch
Security Operations
Bait and Switch Honeypot on SecurityListing: An active and aggressive honeypot tool for network security.

Coralogix DataPrime Engine
Security Information and Event Management
Coralogix DataPrime Engine on SecurityListing: Observability platform with unified query engine for logs, metrics, and traces

Coro Cybersecurity
Security Awareness Training
Coro Cybersecurity on SecurityListing: Unified cybersecurity platform with modular security controls and AI engine

Practical Memory Forensics
Digital Forensics and Incident Response
Practical Memory Forensics on SecurityListing: A practical guide to enhancing digital investigations with cutting-edge memory forensics techniques, covering fundamental concepts, tools, and techniques for memory forensics.

Positive Hack Days
Cyber Range Training
Positive Hack Days Fest on SecurityListing: International cybersecurity festival for all, who wants to dive into the world of cyber security and have a great time.

Crowdstrike Charlotte AI
Extended Detection and Response
Crowdstrike Charlotte AI on SecurityListing: GenAI assistant that provides faster intelligence for security operations

Proxmark III
Offensive Security
Proxmark III on SecurityListing: A tool for testing and analyzing RFID and NFC tags, allowing users to read and write data, and perform various attacks and tests.

Executing Commands and
Offensive Security
Executing Commands and Bypassing AppLocker with PowerShell Diagnostic Scripts on SecurityListing: A blog post about bypassing AppLocker using PowerShell diagnostic scripts

HIHAT - High
Threat Intelligence Platforms
HIHAT - High Interaction Honeypot Analysis Toolkit on SecurityListing: A toolkit that transforms PHP applications into web-based high-interaction Honeypots for monitoring and analyzing attacks.

TechTarget
Offensive Security
TechTarget on SecurityListing: Sysreptor provides a customizable security reporting solution for penetration testers and red teamers.

With Secure Elements
Exposure Management
With Secure Elements Platform on SecurityListing: WithSecure Elements Cloud is a modular cybersecurity platform that combines AI-powered software and expert services to provide comprehensive protection across endpoints, identities, and cloud environments.

Belkasoft X Forensic
Digital Forensics and Incident Response
Belkasoft X Forensic on SecurityListing: A reliable end-to-end DFIR solution for boosting cyber incident response and forensics capacity.

DEF CON CTF
Container Security
DEF CON CTF Archive on SecurityListing: A live archive of DEF CON CTF challenges, vulnerable by design, for hackers to play safely.

Daniel Miessler/Unsupervised Learning
Offensive Security
Daniel Miessler/Unsupervised Learning on SecurityListing: Sysreptor offers a customizable reporting solution for offensive security assessments.

CyberCPR
Digital Forensics and Incident Response
CyberCPR on SecurityListing: Incident response and case management solution for efficient incident response and management.

LastActivityView
Digital Forensics and Incident Response
LastActivityView on SecurityListing: A tool that collects and displays user activity and system events on a Windows system.

Contagio Mobile
Digital Forensics and Incident Response
Contagio Mobile on SecurityListing: A collection of Android Fakebank and Tizi samples for analyzing spyware on Android devices.

CrowdStrike Community Tools
Digital Forensics and Incident Response
CrowdStrike Community Tools on SecurityListing: Free tools for the CrowdStrike customer community to support their use of the Falcon platform.

Dynatrace
Security Information and Event Management
Dynatrace on SecurityListing: Unified observability and security platform with AI-powered analytics

Hunters Next-Gen SIEM
Threat Hunting
Hunters Next-Gen SIEM on SecurityListing: Next-gen SIEM with AI-powered triage, automated investigation & detection

Mandiant Managed Defense
Threat Hunting
Mandiant Managed Defense on SecurityListing: 24/7 managed threat detection, investigation, and response service

0xf.at Hackits
Cyber Range Training
0xf.at Hackits on SecurityListing: Solve password-riddles on a website without logins or ads.

Prophet Security Prophet
Threat Hunting
Prophet Security Prophet AI Threat Hunter on SecurityListing: AI-driven threat hunting platform for SOC alert triage and investigation

Prophet Security Prophet
Security Orchestration Automation and Response
Prophet Security Prophet AI SOC Analyst on SecurityListing: AI-powered SOC analyst that automates alert triage and investigation

IO Wargame
Cyber Range Training
IO Wargame on SecurityListing: Frontpage of the IO wargame with various versions and connection details.

HoneyView
Security Operations
HoneyView on SecurityListing: HoneyView is a tool for analyzing honeyd logfiles graphically and textually.

OODA-driven SOC Strategy
Endpoint Detection and Response
OODA-driven SOC Strategy on SecurityListing: Utilizing SIEM, SOAR, and EDR technologies to enhance security operations with a focus on reducing incident response time.

LaBrea
Penetration Testing
LaBrea on SecurityListing: LaBrea is a 'sticky' honeypot and IDS tool that traps malicious actors by creating virtual servers on unused IP addresses.

Highlighter
Threat Hunting
Highlighter on SecurityListing: Highlighter is a FireEye Market app that integrates with FireEye products to provide enhanced cybersecurity capabilities.

Heimdal Unified Cybersecurity
Endpoint Detection and Response
Heimdal Unified Cybersecurity Platform on SecurityListing: Unified cybersecurity platform with XDR, EDR, PAM, email security, and compliance

Logsign Unified Security
Threat Intelligence Platforms
Logsign Unified Security Operations Platform on SecurityListing: Unified security operations platform combining SIEM, TI, UEBA, and TDIR

Graylog Graylog
API Security
Graylog Graylog on SecurityListing: AI-powered SIEM, API security, and log management platform

Operating System Based
Offensive Security
Operating System Based Redirection with Apache mod_rewrite on SecurityListing: Detect users' operating systems and perform redirection with Apache mod_rewrite.

Prophet Security Prophet
Security Orchestration Automation and Response
Prophet Security Prophet AI on SecurityListing: AI-driven SOC platform for automated alert triage, investigation & response

CyberSight Demo
Security Information and Event Management
CyberSight Demo on SecurityListing: Client-facing dashboard for cybersecurity posture visibility and monitoring

Golismero
Threat Hunting
Golismero on SecurityListing: A free and open-source OSINT framework for gathering and analyzing data from various sources

PTJunior
Offensive Security
PTJunior on SecurityListing: AI agent that autonomously discovers, exploits, and documents vulnerabilities.

D3 Security Smart
Threat Intelligence Platforms
D3 Security Smart SOAR on SecurityListing: SOAR platform for security orchestration, automation, and incident response

Java Decompiler Online
Offensive Security
Java Decompiler Online on SecurityListing: Online Java decompiler tool with support for modern Java features.

CyberMaxx MaxxMDR
Endpoint Detection and Response
CyberMaxx MaxxMDR on SecurityListing: MDR solution combining threat detection, response, and offensive security

Gravwell
Security Information and Event Management
Gravwell on SecurityListing: Data analytics platform for security operations with search and automation

Netdude
Digital Forensics and Incident Response
Netdude on SecurityListing: Network Dump data Displayer and Editor framework for tcpdump trace files manipulation.

Logsign SAP Security
Security Information and Event Management
Logsign SAP Security on SecurityListing: SIEM platform for SAP security monitoring and threat detection

Caldera
Offensive Security
Caldera on SecurityListing: Caldera is a cybersecurity framework by MITRE for automated security assessments and adversary emulation.

BluSapphire SIEMless™ SIEM
Security Information and Event Management
BluSapphire SIEMless™ SIEM on SecurityListing: Distributed SIEM with edge processing, AI filtering, and autonomous response

Empire Communication Profiles
Offensive Security
Empire Communication Profiles on SecurityListing: Customize Empire's GET request URIs, user agent, and headers for evading detection and masquerading as other applications.

Detecting the Elusive
Threat Hunting
Detecting the Elusive - Active Directory Threat Hunting on SecurityListing: A comprehensive resource for threat hunting in Active Directory environments, covering tracking command-line/PowerShell activity, Kerberoasting detection, auditing attacker activity, and monitoring enterprise command-line activity.

Logz.io Observability Platform
Security Information and Event Management
Logz.io Observability Platform on SecurityListing: Observability platform with log mgmt, metrics, tracing & AI-powered RCA

Forensic Registry EDitor
Digital Forensics and Incident Response
Forensic Registry EDitor (FRED) on SecurityListing: A cross-platform registry hive editor for forensic analysis with advanced features like hex viewer and reporting engine.

JS NICE
Digital Forensics and Incident Response
JS NICE on SecurityListing: Statistical renaming, Type inference, and Deobfuscation tool for JavaScript code.

Echotrail Insights
Digital Forensics and Incident Response
Echotrail Insights on SecurityListing: Search engine for Windows executable files and hashes, providing insights into file prevalence, behavior, and security information.

Binary Ninja
Digital Forensics and Incident Response
Binary Ninja on SecurityListing: Binary Ninja is an interactive decompiler, disassembler, debugger, and binary analysis platform with a focus on automation and a clean GUI.

Coro Platform
Data Loss Prevention
Coro Platform on SecurityListing: Unified cybersecurity platform with multiple security modules and single agent

dfir.org
Digital Forensics and Incident Response
dfir.org on SecurityListing: Andrew Case's personal page for research, software projects, and speaking events

Metasploit Unleashed
Penetration Testing
Metasploit Unleashed on SecurityListing: Free online ethical hacking course covering penetration testing, web app assessments, exploit development, and security operations.

Devo Platform
Threat Intelligence Platforms
Devo Platform on SecurityListing: Integrated SIEM, SOAR, and UEBA platform with AI-driven threat detection

Log Parser Lizard
Security Information and Event Management
Log Parser Lizard on SecurityListing: A dynamic GUI for advanced log analysis, allowing users to execute SQL queries on structured log data.

Axoflow Platform
Security Information and Event Management
Axoflow Platform on SecurityListing: Security data pipeline platform for collecting, curating, and routing logs

bohops Leveraging INF-SCT
Offensive Security
bohops Leveraging INF-SCT Fetch & Execute Techniques For Bypass, Evasion, & Persistence on SecurityListing: A blog post discussing INF-SCT fetch and execute techniques for bypass, evasion, and persistence

D3 Smart SOAR
Threat Hunting
D3 Smart SOAR on SecurityListing: SOAR platform with automated threat hunting and investigation capabilities

DNIF HYPERCLOUD
Threat Hunting
DNIF HYPERCLOUD on SecurityListing: SIEM platform with user analytics and automation for threat detection

Viper
Digital Forensics and Incident Response
Viper on SecurityListing: A binary analysis and management framework for organizing and analyzing malware and exploit samples, and creating plugins.

Intezer
Threat Hunting
Intezer on SecurityListing: Intezer is a cloud-based malware analysis platform that detects and classifies malware using genetic code analysis.

CyberForce
Threat Intelligence Platforms
CyberForce|Q COSOC on SecurityListing: 24x7x365 Security Operations Center with threat detection and response services

ARM Assembly and
Offensive Security
ARM Assembly and Shellcode on SecurityListing: A comprehensive collection of resources for learning ARM assembly language and shellcode development.

Fraud.com aiReflex
Risk Assessment
Fraud.com aiReflex on SecurityListing: AI-powered fraud detection platform for transaction monitoring and prevention

Ekasha Incident Management
Security Orchestration Automation and Response
Ekasha Incident Management on SecurityListing: Incident management platform with automation, workflows, and playbooks

Granef
Digital Forensics and Incident Response
Granef on SecurityListing: A network forensics toolkit that transforms network traffic data into graph-based representations for interactive analysis and visualization through a web interface.

Guardpot AI-Powered Cyber
Threat Intelligence Platforms
Guardpot AI-Powered Cyber Deception on SecurityListing: AI-powered deception platform using honeypots to detect & disrupt attacks

Huntress Managed Security
Endpoint Detection and Response
Huntress Managed Security Platform on SecurityListing: Managed security platform with EDR, ITDR, SIEM, and SAT backed by 24/7 SOC

Netenrich Adaptive MDR
Threat Intelligence Platforms
Netenrich Adaptive MDR on SecurityListing: AI-powered MDR service with Google SecOps integration for threat detection

Graylog AI-Powered Security
API Security
Graylog AI-Powered Security on SecurityListing: AI-powered SIEM, API security, and log management platform

Hunters SOC Platform
Threat Hunting
Hunters SOC Platform on SecurityListing: Next-gen SIEM with AI-powered alert investigation and automated response

Honeybrid
Network Security
Honeybrid on SecurityListing: A hybrid honeypot framework that combines low and high interaction honeypots for network security

THOR Lite
Digital Forensics and Incident Response
THOR Lite on SecurityListing: A free, fast, and flexible multi-platform IOC and YARA scanner for Windows, Linux, and macOS.

DBAppSecurity AiLog Big
Threat Intelligence Platforms
DBAppSecurity AiLog Big Data Log Management and Analysis Platform on SecurityListing: Big data log management platform for collection, parsing, storage & analysis

ERM Protect Digital
Digital Forensics and Incident Response
ERM Protect Digital Forensics on SecurityListing: Digital forensics services provided by ERM Protect

Bastille-Linux
Offensive Security
Bastille-Linux on SecurityListing: Bastille-Linux is a system hardening program that proactively configures the system for increased security and educates users about security settings.

Quorum Cyber Clarity
Threat Hunting
Quorum Cyber Clarity Extend on SecurityListing: Managed detection and response service with 24/7 SOC monitoring

edb
Digital Forensics and Incident Response
edb on SecurityListing: edb is a powerful debugger for Linux binaries, enhancing reverse engineering efforts with a user-friendly interface and extensible plugins.

Proxmark 3
Offensive Security
Proxmark 3 on SecurityListing: The Proxmark III is a versatile device for sniffing, reading, and cloning RFID tags with strong community support.

checkra1n
Offensive Security
checkra1n on SecurityListing: Semi-tethered jailbreak for iPhone 5s to iPhone X, running iOS 12.0 and up, using the 'checkm8' bootrom exploit.

strings
Digital Forensics and Incident Response
strings on SecurityListing: A command-line utility for extracting human-readable text from binary files.

LeakIX
Offensive Security
LeakIX on SecurityListing: LeakIX is a red-team search engine that indexes mis-configurations and vulnerabilities online.

Gradient Cyber Quorum™
Threat Intelligence Platforms
Gradient Cyber Quorum™ on SecurityListing: Unified threat detection platform for network, endpoint, cloud, and user telemetry

Loading Alternate Data
Offensive Security
Loading Alternate Data Stream (ADS) DLL/CPL Binaries to Bypass AppLocker on SecurityListing: Utilizing Alternate Data Streams (ADS) to bypass AppLocker default policies by loading DLL/CPL binaries.

Randomized Malleable C2
Penetration Testing
Randomized Malleable C2 Profiles Made Easy on SecurityListing: Tool for randomizing Cobalt Strike Malleable C2 profiles to evade static, signature-based detection controls.

Lumifi Endpoint Detection
Endpoint Detection and Response
Lumifi Endpoint Detection & Response (EDR/XDR) on SecurityListing: Managed EDR/XDR service with 24/7 SOC monitoring and threat response

NETRESEC
Digital Forensics and Incident Response
NETRESEC on SecurityListing: Independent software vendor specializing in network security tools and network forensics.

Workbench
Digital Forensics and Incident Response
Workbench on SecurityListing: A scalable python framework for security research and development teams.

Logz.io Infrastructure Monitoring
Security Information and Event Management
Logz.io Infrastructure Monitoring on SecurityListing: Prometheus-based infrastructure monitoring with unified logs, metrics, and traces

Catalyst SOAR
Security Orchestration Automation and Response
Catalyst SOAR on SecurityListing: Catalyst is a SOAR system that automates alert handling and incident response processes, adapting to your workflows and being open source.

Google Search Operators:
Threat Hunting
Google Search Operators: The Complete List (44 Advanced Operators) on SecurityListing: A reference guide listing 44 advanced Google search operators for enhanced search filtering and precision in information gathering activities.

dc3dd
Digital Forensics and Incident Response
dc3dd on SecurityListing: dc3dd is a patch to the GNU dd program, tailored for forensic acquisition with features like hashing and file verification.

Abusing Exported Functions
Offensive Security
Abusing Exported Functions and Exposed DCOM Interfaces for Pass-Thru Command Execution and Lateral Movement on SecurityListing: A blog post about abusing exported functions and exposed DCOM interfaces for pass-thru command execution and lateral movement

FastIntercept
Security Orchestration Automation and Response
FastIntercept on SecurityListing: Fast Intercept is a security automation platform that empowers users to maximize their existing security products and automate routine tasks.

LogRhythm Axon
Security Information and Event Management
LogRhythm Axon on SecurityListing: A cloud-native SIEM platform that provides security analytics, intuitive workflow, and simplified incident response to help security teams defend against cyber threats.

Huawei SecoManager Security
Security Orchestration Automation and Response
Huawei SecoManager Security Controller on SecurityListing: Security controller for policy mgmt, orchestration & log management

netsniff-ng toolkit
Digital Forensics and Incident Response
netsniff-ng toolkit on SecurityListing: netsniff-ng is a free Linux networking toolkit with zero-copy mechanisms for network development, analysis, and auditing.

GroupSense Ransomware Readiness
Digital Risk Protection
GroupSense Ransomware Readiness on SecurityListing: Ransomware preparedness & response service with playbooks and negotiation

Kojoney
Security Operations
Kojoney on SecurityListing: A honeypot for the SSH Service

extundelete
Digital Forensics and Incident Response
extundelete on SecurityListing: A utility for recovering deleted files from ext3 or ext4 partitions.

Foremost
Digital Forensics and Incident Response
Foremost on SecurityListing: A console program for file recovery through data carving.

Amazon Detective
Digital Forensics and Incident Response
Amazon Detective on SecurityListing: A service that analyzes and visualizes security data to investigate potential security issues.

Charles Web Debugging
Digital Forensics and Incident Response
Charles Web Debugging Proxy on SecurityListing: An HTTP proxy, monitor, and reverse proxy tool for viewing HTTP and SSL/HTTPS traffic.

LockBoxx
Offensive Security
LockBoxx on SecurityListing: Introduction to using GScript for Red Teams

Mature SIEM Environment
Security Orchestration Automation and Response
Mature SIEM Environment for SOAR Implementation on SecurityListing: A mature SIEM environment is critical for successful SOAR implementation.

Cribl Edge
Security Information and Event Management
Cribl Edge on SecurityListing: Vendor-neutral agent for unified telemetry collection across distributed infra

Seceon aiSIEM CGuard
Security Information and Event Management
Seceon aiSIEM CGuard 2.0 on SecurityListing: AI-powered SIEM for cloud security across Microsoft 365, Azure, AWS, and GCP

Radiant Agentic AI
Threat Hunting
Radiant Agentic AI on SecurityListing: AI-powered SOC platform for automated alert triage, incident response & logging

Trust Direction: An
Offensive Security
Trust Direction: An Enabler for Active Directory Enumeration and Trust Exploitation on SecurityListing: A blog post explaining the concept of Active Directory Trusts and their enumeration and exploitation

SecGame #1: Sauron
Penetration Testing
SecGame #1: Sauron on SecurityListing: A Linux-based environment for penetration testing and vulnerability exploitation

RTIR
Digital Forensics and Incident Response
RTIR on SecurityListing: Request Tracker for Incident Response (RTIR) is a tool for incident response teams to manage incident reports, correlate data, and facilitate communication.

Reveald ManagedDetection and
Threat Hunting
Reveald ManagedDetection and Response on SecurityListing: MDR service for CrowdStrike, Microsoft, and Trellix endpoints with 24/7 monitoring

Preparing for Red
Penetration Testing
Preparing for Red Team at PRCCDC 2015 on SecurityListing: Preparation process for participating in the Pacific Rim CCDC 2015.

DDE attack with
Offensive Security
DDE attack with PowerShell Empire on SecurityListing: Weaponize Word documents with PowerShell Empire using the Microsoft DDE exploit.

StrangeBee TheHive
Security Orchestration Automation and Response
StrangeBee TheHive on SecurityListing: Security case management platform for SOCs, CERTs, and CSIRTs

xxd
Digital Forensics and Incident Response
xxd on SecurityListing: A command-line tool for creating hex dumps, converting between binary and human-readable representations, and patching binary files.

WindowsSCOPE
Digital Forensics and Incident Response
WindowsSCOPE on SecurityListing: A comprehensive incident response tool for Windows computers, providing advanced memory forensics and access to locked systems.

The Security Ledger
Offensive Security
The Security Ledger on SecurityListing: Sysreptor offers a customizable reporting solution for pentesters and red teamers to enhance security documentation.

Webhacking.kr
Vulnerability Assessment
Webhacking.kr on SecurityListing: Korean cyber-security challenge platform for exploiting and defending web application vulnerabilities.

Sumo Logic Application
Security Information and Event Management
Sumo Logic Application Modernization on SecurityListing: Cloud-based log analytics & monitoring platform for app modernization