Awesome Cybersecurity Blue Team
:computer:🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.
Cybersecurity blue teamsare groups of individuals who identify security flaws in information technology systems, verify the effectiveness of…
DEFUND THE POLICE.Ansible LockdownCurated collection of information security themed Ansible roles that are both vetted and actively maintained.
ClevisPlugable framework for automated decryption, often used as a Tang client.
DShellExtensible network forensic analysis framework written in Python that enables rapid development of plugins to support…
Dev-Sec.ioServer hardening framework providing Ansible, Chef, and Puppet implementations of various baseline security…
Password Manager ResourcesCollaborative, crowd-sourced data and code to make password management better.
peepdfScriptable PDF file analyzer.
PyREBoxPython-scriptable reverse engineering sandbox, based on QEMU.
WatchtowerContainer-based solution for automating Docker container base image updates, providing an unattended upgrade experience.
MultiScannerFile analysis framework written in Python that assists in evaluating a set of files by automatically running a suite…
Posh-VirusTotalPowerShell interface to VirusTotal.com APIs.
censys-pythonPython wrapper to the Censys REST API.
libcrafterHigh level C++ network packet sniffing and crafting library.
python-dshieldPythonic interface to the Internet Storm Center/DShield API.
python-sandboxapiMinimal, consistent Python API for building integrations with malware sandboxes.
python-stix2Python APIs for serializing and de-serializing Structured Threat Information eXpression (STIX) JSON content, plus…
ShuffleGraphical generalized workflow (automation) builder for IT professionals and blue teamers.
AaiaHelps in visualizing AWS IAM and Organizations in a graph format with help of Neo4j.
FalcoBehavioral activity monitor designed to detect anomalous activity in containerized applications, hosts, and network…
Kata ContainersSecure container runtime with lightweight virtual machines that feel and perform like containers, but provide stronger…
Principal Mapper (PMapper)Quickly evaluate IAM permissions in AWS via script and library capable of identifying risks in the configuration of…
ProwlerTool based on AWS-CLI commands for Amazon Web Services account security assessment and hardening.
Scout SuiteOpen source multi-cloud security-auditing tool, which enables security posture assessment of cloud environments.
gVisorApplication kernel, written in Go, that implements a substantial portion of the Linux system surface to provide an…
CortexProvides horizontally scalable, highly available, multi-tenant, long term storage for Prometheus.
JaegerDistributed tracing platform backend used for monitoring and troubleshooting microservices-based distributed systems.
OpenTelemetryObservability framework for cloud-native software, comprising a collection of tools, APIs, and SDKs for exporting…
PrometheusOpen-source systems monitoring and alerting toolkit originally built at SoundCloud.
ZipkinDistributed tracing system backend that helps gather timing data needed to troubleshoot latency problems in service…
KubeSecStatic analyzer of Kubernetes manifests that can be run locally, as a Kuberenetes admission controller, or as its own…
KyvernoPolicy engine designed for Kubernetes.
LinkerdUltra light Kubernetes-specific service mesh that adds observability, reliability, and security to Kubernetes…
Managed Kubernetes Inspection Tool (MKIT)Query and validate several common security-related configuration settings of managed Kubernetes cluster objects and…
PolarisValidates Kubernetes best practices by running tests against code commits, a Kubernetes admission request, or live…
Sealed SecretsKubernetes controller and tool for one-way encrypted Secrets.
certificate-expiry-monitorUtility that exposes the expiry of TLS certificates as Prometheus metrics.
k-railWorkload policy enforcement tool for Kubernetes.
kube-forensicsAllows a cluster administrator to dump the current state of a running pod and all its containers so that security…
kube-hunterOpen-source tool that runs a set of tests ("hunters") for security issues in Kubernetes clusters from either outside…
kubernetes-event-exporterAllows exporting the often missed Kubernetes events to various outputs so that they can be used for observability or…
ConsulSolution to connect and configure applications across dynamic, distributed infrastructure and, with Consul Connect,…
IstioOpen platform for providing a uniform way to integrate microservices, manage traffic flow across microservices,…
GPG SyncCentralize and automate OpenPGP public key distribution, revocation, and updates amongst all members of an…
Geneva (Genetic Evasion)Novel experimental genetic algorithm that evolves packet-manipulation-based censorship evasion strategies against…
GlobaLeaksFree, open source software enabling anyone to easily set up and maintain a secure whistleblowing platform.
SecureDropOpen source whistleblower submission system that media organizations and NGOs can install to securely accept documents…
TeleportAllows engineers and security professionals to unify access for SSH servers, Kubernetes clusters, web applications,…
BaneCustom and better AppArmor profile generator for Docker containers.
BlackBoxSafely store secrets in Git/Mercurial/Subversion by encrypting them "at rest" using GnuPG.
CheckovStatic analysis for Terraform (infrastructure as code) to help detect CIS policy violations and prevent cloud security…
CiliumOpen source software for transparently securing the network connectivity between application services deployed using…
ClairStatic analysis tool to probe for vulnerabilities introduced via application container (e.g., Docker) images.
CodeQLDiscover vulnerabilities across a codebase by performing queries against code as though it were data.
DefectDojoApplication vulnerability management tool built for DevOps and continuous security integration.
GauntltPentest applications during routine continuous integration build pipelines.
Git SecretsPrevents you from committing passwords and other sensitive information to a git repository.
SOPSEditor of encrypted files that supports YAML, JSON, ENV, INI and binary formats and encrypts with AWS KMS, GCP KMS,…
SnykFinds and fixes vulnerabilities and license violations in open source dependencies and container images.
SonarQubeContinuous inspection tool that provides detailed reports during automated testing and alerts on newly introduced…
TrivySimple and comprehensive vulnerability scanner for containers and other artifacts, suitable for use in continuous…
VaultTool for securely accessing secrets such as API keys, passwords, or certificates through a unified interface.
git-cryptTransparent file encryption in git; files which you choose to protect are encrypted when committed, and decrypted when…
helm-secretsHelm plugin that helps manage secrets with Git workflow and stores them anywhere, backed by SOPS.
terrascanStatic code analyzer for Infrastructure as Code tools that helps detect compliance and security violations to mitigate…
tfsecStatic analysis security scanner for your Terraform code designed to run locally and in CI pipelines.
DynInstTools for binary instrumentation, analysis, and modification, useful for binary patching.
DynamoRIORuntime code manipulation system that supports code transformations on any part of a program, while it executes,…
EgalitoBinary recompiler and instrumentation framework that can fully disassemble, transform, and regenerate ordinary Linux…
ValgrindInstrumentation framework for building dynamic analysis tools.
Chef InSpecLanguage for describing security and compliance rules, which become automated tests that can be run against IT…
OpenSCAP BaseBoth a library and a command line tool (oscap) used to evaluate a system against SCAP baseline profiles to report on…
Dependency CombobulatorOpen source, modular and extensible framework to detect and prevent dependency confusion leakage and potential attacks.
Confusion checkerScript to check if you have artifacts containing the same name between your repositories.
snyncPrevent and detect if you're vulnerable to dependency confusion supply chain security attacks.
AtherisCoverage-guided Python fuzzing engine based off of libFuzzer that supports fuzzing of Python code but also native…
FuzzBenchFree service that evaluates fuzzers on a wide variety of real-world benchmarks, at Google scale.
OneFuzzSelf-hosted Fuzzing-as-a-Service (FaaS) platform.
AllStarGitHub App installed on organizations or repositories to set and enforce security policies.
ConftestUtility to help you write tests against structured configuration data.
Open Policy Agent (OPA)Unified toolset and framework for policy across the cloud native stack.
RegulaChecks infrastructure as code templates (Terraform, CloudFormation, K8s manifests) for AWS, Azure, Google Cloud, and…
TangServer for binding data to network presence; provides data to clients only when they are on a certain (secured) network.
GrafeasOpen artifact metadata API to audit and govern your software supply chain.
Helm GPG (GnuPG) PluginChart signing and verification with GnuPG for Helm.
NotaryAims to make the internet more secure by making it easy for people to publish and verify content.
in-totoFramework to secure the integrity of software supply chains.
CanaryTokensSelf-hostable honeytoken generator and reporting dashboard; demo version available at CanaryTokens.org.
KushtakaSustainable all-in-one honeypot and honeytoken orchestrator for under-resourced blue teams.
ManukaOpen-sources intelligence (OSINT) honeypot that monitors reconnaissance attempts by threat actors and generates…
EndlesshSSH tarpit that slowly sends an endless banner.
LaBreaProgram that answers ARP requests for unused IP space, creating the appearance of fake machines that answer further…
ArtilleryCombination honeypot, filesystem monitor, and alerting system designed to protect Linux and Windows operating systems.
Crowd InspectFree tool for Windows systems aimed to alert you to the presence of malware that may be communicating over the network.
Fail2banIntrusion prevention software framework that protects computer servers from brute-force attacks.
Open Source HIDS SECurity (OSSEC)Fully open source and free, feature-rich, Host-based Instrusion Detection System (HIDS).
Rootkit Hunter (rkhunter)POSIX-compliant Bash script that scans a host for various signs of malware.
ShufflecakePlausible deniability for multiple hidden filesystems on Linux.
USB Keystroke Injection ProtectionDaemon for blocking USB keystroke injection devices on Linux systems.
chkrootkitLocally checks for signs of a rootkit on GNU/Linux systems.
BubblewrapSandboxing tool for use by unprivileged Linux users capable of restricting access to parts of the operating system or…
DangerzoneTake potentially dangerous PDFs, office documents, or images and convert them to a safe PDF.
FirejailSUID program that reduces the risk of security breaches by restricting the running environment of untrusted…
Gluu ServerCentral authentication and authorization for Web and mobile applications with a Free and Open Source Software…
LogonTracerInvestigate malicious Windows logon by visualizing and analyzing Windows event log.
VolatilityAdvanced memory forensics framework.
aws_irAutomates your incident response with zero security preparedness assumptions.
CIRTKitScriptable Digital Forensics and Incident Response (DFIR) toolkit built on Viper.
Fast Incident Response (FIR)Cybersecurity incident management platform allowing for easy creation, tracking, and reporting of cybersecurity…
RekallAdvanced forensic and incident response framework.
TheHiveScalable, free Security Incident Response Platform designed to make life easier for SOCs, CSIRTs, and CERTs, featuring…
threat_noteWeb application built by Defense Point Security to allow security researchers the ability to add and retrieve…
AutoMacTCModular, automated forensic triage collection framework designed to access various forensic artifacts on macOS, parse…
OSXAuditorFree macOS computer forensics tool.
OSXCollectorForensic evidence collection & analysis toolkit for macOS.
ir-rescueWindows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.
Margarita ShotgunCommand line utility (that works with or without Amazon EC2 instances) to parallelize remote memory acquisition.
Untitled Goose ToolAssists incident response teams by exporting cloud artifacts from Azure/AzureAD/M365 environments in order to run a…
GatekeeperFirst open source Distributed Denial of Service (DDoS) protection system.
fwknopProtects ports via Single Packet Authorization in your firewall.
ssh-auditSimple tool that makes quick recommendations for improving an SSH server's security posture.
IPFireHardened GNU/Linux based router and firewall distribution forked from IPCop.
OPNsenseHardened FreeBSD based firewall and routing platform forked from pfSense.
pfSenseFreeBSD firewall and router distribution forked from m0n0wall.
Computer Aided Investigative Environment (CAINE)Italian GNU/Linux live distribution that pre-packages numerous digital forensics and evidence collection tools.
Security OnionFree and open source GNU/Linux distribution for intrusion detection, enterprise security monitoring, and log management.
Qubes OSDesktop environment built atop the Xen hypervisor project that runs each end-user program in its own virtual machine…
CertSpotterCertificate Transparency log monitor from SSLMate that alerts you when a SSL/TLS certificate is issued for one of your…
GophishPowerful, open-source phishing framework that makes it easy to test your organization's exposure to phishing.
King PhisherTool for testing and promoting user awareness by simulating real world phishing attacks.
NotifySecurityOutlook add-in used to help your users to report suspicious e-mails to security teams.
Phishing Intelligence Engine (PIE)Framework that will assist with the detection and response to phishing attacks.
SwordphishPlatform allowing to create and manage (fake) phishing campaigns intended to train people in identifying suspicious…
mailspoofScans SPF and DMARC records for issues that could allow email spoofing.
phishing_catcherConfigurable script to watch for issuances of suspicious TLS certificates by domain name in the Certificate…
APTSimulatorToolset to make a system look as if it was the victim of an APT attack.
Atomic Red TeamLibrary of simple, automatable tests to execute for testing security controls.
BadBloodFills a test (non-production) Windows Domain with data that enables security analysts and engineers to practice using…
CalderaScalable, automated, and extensible adversary emulation platform developed by MITRE.
DroolReplay DNS traffic from packet capture files and send it to a specified server, such as for simulating DDoS attacks on…
DumpsterFireModular, menu-driven, cross-platform tool for building repeatable, time-delayed, distributed security events for Blue…
Infection MonkeyOpen-source breach and attack simulation (BAS) platform that helps you validate existing controls and identify how…
MettaAutomated information security preparedness tool to do adversarial simulation.
Network Flight Simulator (flightsim)Utility to generate malicious network traffic and help security teams evaluate security controls and audit their…
RedHunt OSUbuntu-based Open Virtual Appliance (.ova) preconfigured with several threat emulation tools as well as a defender's…
Stratus Red TeamEmulate offensive attack techniques in a granular and self-contained manner against a cloud environment; think "Atomic…
tcpreplaySuite of free Open Source utilities for editing and replaying previously captured network traffic originally designed…
RedEyeAnalytic tool to assist both Red and Blue teams with visualizing and reporting command and control activities, replay…
Bunkerized-nginxDocker image of an NginX configuration and scripts implementing many defensive techniques for Web sites.
CrossfeedContinuously enumerates and monitors an organization’s public-facing attack surface in order to discover assets and…
StarbaseCollects assets and relationships from services and systems into an intuitive graph view to offer graph-based security…
WazuhOpen source, multiplatform agent-based security monitoring based on a fork of OSSEC HIDS.
ArkimeAugments your current security infrastructure to store and index network traffic in standard PCAP format, providing…
ChopShopFramework to aid analysts in the creation and execution of pynids-based decoders and detectors of APT tradecraft.
MaltrailMalicious network traffic detection system.
OwlHHelps manage network IDS at scale by visualizing Suricata, Zeek, and Moloch life cycles.
Real Intelligence Threat Analysis (RITA)Open source framework for network traffic analysis that ingests Zeek logs and detects beaconing, DNS tunneling, and…
RespounderDetects the presence of the Responder LLMNR/NBT-NS/MDNS poisoner on a network.
SnortWidely-deployed, Free Software IPS capable of real-time packet analysis, traffic logging, and custom rule-based…
SpoofSpotterCatch spoofed NetBIOS Name Service (NBNS) responses and alert to an email or log file.
StenographerFull-packet-capture utility for buffering packets to disk for intrusion detection and incident response purposes.
SuricataFree, cross-platform, IDS/IPS with on- and off-line analysis modes and deep packet inspection capabilities that is…
TsunamiGeneral purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities…
VASTFree and open-source network telemetry engine for data-driven security investigations.
WiresharkFree and open-source packet analyzer useful for network troubleshooting or forensic netflow analysis.
ZeekPowerful network analysis framework focused on security monitoring, formerly known as Bro.
netsniff-ngFree and fast GNU/Linux networking toolkit with numerous utilities such as a connection tracking tool (flowtop),…
AlienVault OSSIMSingle-server open source SIEM platform featuring asset discovery, asset inventorying, behavioral monitoring, and…
Prelude SIEM OSSOpen source, agentless SIEM with a long history and several commercial variants featuring security event collection,…
IcingaModular redesign of Nagios with pluggable user interfaces and an expanded set of data connectors, collectors, and…
LocustOpen source load testing tool in which you can define user behaviour with Python code and swarm your system with…
NagiosPopular network and service monitoring solution and reporting platform.
OpenNMSFree and feature-rich networking monitoring system supporting multiple configurations, a variety of alerting…
osqueryOperating system instrumentation framework for macOS, Windows, and Linux, exposing the OS as a high-performance…
ZabbixMature, enterprise-level platform to monitor large-scale IT environments.
CimSweepSuite of CIM/WMI-based tools enabling remote incident response and hunting operations across all versions of Windows.
DeepBlueCLIPowerShell module for hunt teaming via Windows Event logs.
GRR Rapid ResponseIncident response framework focused on remote live forensics consisting of a Python agent installed on assets and…
Hunting ELK (HELK)All-in-one Free Software threat hunting stack based on Elasticsearch, Logstash, Kafka, and Kibana with various…
Logging Made Easy (LME)Free and open logging and protective monitoring solution serving.
MozDefAutomate the security incident handling process and facilitate the real-time activities of incident handlers.
PSHuntPowerShell module designed to scan remote endpoints for indicators of compromise or survey them for more comprehensive…
PSReconPSHunt-like tool for analyzing remote Windows systems that also produces a self-contained HTML report of its findings.
PowerForensicsAll in one PowerShell-based platform to perform live hard disk forensic analysis.
RedlineFreeware endpoint auditing and analysis tool that provides host-based investigative capabilities, offered by FireEye,…
rastrea2rMulti-platform tool for triaging suspected IOCs on many endpoints simultaneously and that integrates with antivirus…
AttackerKBFree and public crowdsourced vulnerability assessment platform to help prioritize high-risk patch application and…
DATACredential phish analysis and automation tool that can accept suspected phishing URLs directly or trigger on observed…
ForagerMulti-threaded threat intelligence gathering built with Python3 featuring simple text-based configuration and data…
GRASSMARLINProvides IP network situational awareness of industrial control systems (ICS) and Supervisory Control and Data…
MLSec CombineGather and combine multiple threat intelligence feed sources into one customizable, standardized CSV-based format.
Malware Information Sharing Platform and Threat Sharing (MISP)Open source software solution for collecting, storing, distributing and sharing cyber security indicators.
Open Source Vulnerabilities (OSV)Vulnerability database and triage infrastructure for open source projects aimed at helping both open source…
SigmaGeneric signature format for SIEM systems, offering an open signature format that allows you to describe relevant log…
Threat BusThreat intelligence dissemination layer to connect security tools through a distributed publish/subscribe message…
ThreatIngestorExtendable tool to extract and aggregate IOCs from threat feeds including Twitter, RSS feeds, or other sources.
UnfetterIdentifies defensive gaps in security posture by leveraging Mitre's ATT&CK framework.
ViperBinary analysis and management framework enabling easy organization of malware and exploit samples.
YARATool aimed at (but not limited to) helping malware researchers to identify and classify malware samples, described as…
HASSHNetwork fingerprinting standard which can be used to identify specific client and server SSH implementations.
JA3Extracts SSL/TLS handshake settings for fingerprinting and communicating about a given TLS implementation.
ESET's Malware IoCsIndicators of Compromises (IOCs) derived from ESET's various investigations.
FireEye's Red Team Tool CountermeasuresCollection of Snort and YARA rules to detect attacks carried out with FireEye's own Red Team tools, first released…
FireEye's Sunburst CountermeasuresCollection of IoC in various languages for detecting backdoored SolarWinds Orion NMS activities and related…
YARA RulesProject covering the need for IT security researchers to have a single repository where different Yara signatures are…
OnionBalanceProvides load-balancing while also making Onion services more resilient and reliable by eliminating single…
VanguardsVersion 3 Onion service guard discovery attack mitigation script (intended for eventual inclusion in Tor core).
CertbotFree tool to automate the issuance and renewal of TLS certificates from the LetsEncrypt Root CA with plugins that…
MITMEngineGolang library for server-side detection of TLS interception events.
TorCensorship circumvention and anonymizing overlay network providing distributed, cryptographically verified name…
FirezoneSelf-hosted VPN server built on WireGuard that supports MFA and SSO.
HeadscaleOpen source, self-hosted implementation of the Tailscale control server.
IPsec VPN Server Auto Setup ScriptsScripts to build your own IPsec VPN server, with IPsec/L2TP, Cisco IPsec and IKEv2.
InnernetFree Software private network system that uses WireGuard under the hood, made to be self-hosted.
NebulaCompletely open source and self-hosted, scalable overlay networking tool with a focus on performance, simplicity, and…
OpenVPNLongstanding Free Software traditional SSL/TLS-based virtual private network.
OpenZITIOpen source initiative focused on bringing Zero Trust to any application via an overlay network, tunelling…
TailscaleManaged freemium mesh VPN service built on top of WireGuard.
WireGuardExtremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography.
tincFree Software mesh VPN implemented entirely in userspace that supports expandable network space, bridged ethernet…
BlockBlockMonitors common persistence locations and alerts whenever a persistent component is added, which helps to detect and…
LuLuFree macOS firewall.
SantaKeep track of binaries that are naughty or nice in an allow/deny-listing system for macOS.
StrongholdEasily configure macOS security settings from the terminal.
macOS FortressAutomated configuration of kernel-level, OS-level, and client-level security features including privatizing proxying…
CobaltStrikeScanScan files or process memory for Cobalt Strike beacons and parse their configuration.
HardenToolsUtility that disables a number of risky Windows features.
NotRulerDetect both client-side rules and VBScript enabled forms used by the Ruler attack tool when attempting to compromise a…
SandboxieFree and open source general purpose Windows application sandboxing utility.
SigcheckAudit a Windows host's root certificate store against Microsoft's Certificate Trust List (CTL).
Sticky Keys SlayerEstablishes a Windows RDP session from a list of hostnames and scans for accessibility tools backdoors, alerting if…
Windows Secure Host BaselineGroup Policy objects, compliance checks, and configuration tools that provide an automated and flexible approach for…
WMI MonitorLog newly created WMI consumers and processes to the Windows Application event log.
Active Directory Control PathsVisualize and graph Active Directory permission configs ("control relations") to audit questions such as "Who can read…
PingCastleActive Directory vulnerability detection and reporting tool.
PlumHoundMore effectively use BloodHoundAD in continual security life-cycles by utilizing its pathfinding engine to identify…