Blueteam Open Source Projects
Browse 103 Blueteam open source projects, ranked by GitHub stars. Find the most popular Blueteam tools and libraries.
laramies/theHarvester
E-mails, subdomains and names Harvester - OSINT
Metrics details
| Stars | 16,843 |
GTFOBins/GTFOBins.github.io
GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.
Metrics details
| Stars | 13,464 |
LOLBAS-Project/LOLBAS
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
Metrics details
| Stars | 8,694 |
yaklang/yakit
Cyber Security ALL-IN-ONE Platform
Metrics details
| Stars | 7,612 |
ihebski/DefaultCreds-cheat-sheet
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
Metrics details
| Stars | 6,678 |
decalage2/awesome-security-hardening
A collection of awesome security hardening guides, tools and other resources
Metrics details
| Stars | 6,469 |
rmusser01/Infosec_Reference
An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.
Metrics details
| Stars | 5,978 |
madhuakula/kubernetes-goat
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
Metrics details
| Stars | 5,719 |
ffffffff0x/1earn
ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup
Metrics details
| Stars | 5,702 |
A-poc/BlueTeam-Tools
Tools and Techniques for Blue Team / Incident Response
Metrics details
| Stars | 4,246 |
snooppr/snoop
Snoop — инструмент разведки на основе открытых данных (OSINT world)
Metrics details
| Stars | 3,970 |
WithSecureLabs/chainsaw
Rapidly Search and Hunt through Windows Forensic Artefacts
Metrics details
| Stars | 3,603 |
JPCERTCC/LogonTracer
Investigate malicious Windows logon by visualizing and analyzing Windows event log
Metrics details
| Stars | 3,193 |
opsdisk/the_cyber_plumbers_handbook
Free copy of The Cyber Plumber's Handbook - The definitive guide to Secure Shell (SSH) tunneling, port redirection, and bending traffic like a boss.
Metrics details
| Stars | 2,879 |
0x6d69636b/windows_hardening
HardeningKitty and Windows Hardening Settings
Metrics details
| Stars | 2,637 |
Mr-xn/RedTeam_BlueTeam_HW
红蓝对抗以及护网相关工具和资料,内存shellcode(cs+msf)和内存马查杀工具
Metrics details
| Stars | 2,629 |
bigb0sss/RedTeam-OffensiveSecurity
Tools & Interesting Things for RedTeam Ops
Metrics details
| Stars | 2,293 |
lkarlslund/Adalanche
Attack Graph Visualizer and Explorer (Active Directory) ...Who's *really* Domain Admin?
Metrics details
| Stars | 2,188 |
api0cradle/UltimateAppLockerByPassList
The goal of this repository is to document the most common techniques to bypass AppLocker.
Metrics details
| Stars | 2,075 |
scipag/HardeningKitty
HardeningKitty - Checks and hardens your Windows configuration
Metrics details
| Stars | 1,794 |
Purp1eW0lf/Blue-Team-Notes
You didn't think I'd go and leave the blue team out, right?
Metrics details
| Stars | 1,756 |
mthcht/awesome-lists
Awesome Security lists for SOC/CERT/CTI
Metrics details
| Stars | 1,751 |
Bert-JanP/Hunting-Queries-Detection-Rules
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
Metrics details
| Stars | 1,721 |
WADComs/WADComs.github.io
WADComs is an interactive cheat sheet, containing a curated list of offensive security tools and their respective commands, to be used against Windows/AD environments.
Metrics details
| Stars | 1,691 |
api0cradle/LOLBAS
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
Metrics details
| Stars | 1,613 |
xiecat/goblin
一款适用于红蓝对抗中的仿真钓鱼系统
Metrics details
| Stars | 1,539 |
PlumHound/PlumHound
Bloodhound Reporting for Blue and Purple Teams
Metrics details
| Stars | 1,299 |
NH-RED-TEAM/RustHound
Active Directory data ingestor for BloodHound Legacy written in Rust. 🦀
Metrics details
| Stars | 1,163 |
cfalta/MicrosoftWontFixList
A list of vulnerabilities or design flaws that Microsoft does not intend to fix. Since the number is growing, I decided to make a list. This list covers only vulnerabilities that came up in July 2021 (and SpoolSample ;-))
Metrics details
| Stars | 953 |
FalconForceTeam/FalconFriday
Hunting queries and detections
Metrics details
| Stars | 916 |
scythe-io/purple-team-exercise-framework
Purple Team Exercise Framework
Metrics details
| Stars | 808 |
emtunc/SlackPirate
Slack Enumeration and Extraction Tool - extract sensitive information from a Slack Workspace
Metrics details
| Stars | 780 |
bluecapesecurity/PWF
Practical Windows Forensics Training
Metrics details
| Stars | 777 |
cyberark/PipeViewer
A tool that shows detailed information about named pipes in Windows
Metrics details
| Stars | 750 |
Zeus-Labs/ZeusCloud
Open Source Cloud Security
Metrics details
| Stars | 732 |
enomothem/Whoamifuck
用于Linux应急响应,快速排查异常用户登录情况和入侵信息排查,准确定位溯源时间线,高效辅助还原攻击链。
Metrics details
| Stars | 684 |
0xDanielLopez/TweetFeed
TweetFeed collects Indicators of Compromise (IOCs) shared by the infosec community at Twitter. Here you will find malicious URLs, domains, IPs, and SHA256/MD5 hashes.
Metrics details
| Stars | 670 |
mthcht/ThreatHunting-Keywords
Awesome list of keywords and artifacts for Threat Hunting sessions
Metrics details
| Stars | 666 |
auth0/repo-supervisor
Scan your code for security misconfiguration, search for passwords and secrets. :mag:
Metrics details
| Stars | 654 |
ffffffff0x/Pentest101
一些关于渗透测试的Tips
Metrics details
| Stars | 612 |
activecm/rita
Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
Metrics details
| Stars | 604 |
loseys/Oblivion
Data leak checker & OSINT Tool
Metrics details
| Stars | 593 |
LewisArdern/bXSS
bXSS is a utility which can be used by bug hunters and organizations to identify Blind Cross-Site Scripting.
Metrics details
| Stars | 577 |
WiPi-Hunter/PiDense
🍓📡🍍Monitor illegal wireless network activities. (Fake Access Points), (WiFi Threats: KARMA Attacks, WiFi Pineapple, Similar SSID, OPN Network Density etc.)
Metrics details
| Stars | 567 |
infosecB/LOOBins
Living Off the Orchard: macOS Binaries (LOOBins) is designed to provide detailed information on various built-in "living off the land" macOS binaries and how they can be used by threat actors for malicious purposes.
Metrics details
| Stars | 542 |
idnahacks/GoodHound
Uses Sharphound, Bloodhound and Neo4j to produce an actionable list of attack paths for targeted remediation.
Metrics details
| Stars | 488 |
redeye-framework/Redeye
Redeye is a tool intended to help you manage your data during a pentest operation
Metrics details
| Stars | 472 |
burpheart/koko-moni
一个基于网络空间搜索引擎的攻击面管理平台,可定时进行资产信息爬取,及时发现新增资产,本项目聚合了 Fofa、Hunter、Quake、Zoomeye 和 Threatbook 的数据源,并对获取到的数据进行去重与清洗
Metrics details
| Stars | 461 |
cyberark/RPCMon
RPC Monitor tool based on Event Tracing for Windows
Metrics details
| Stars | 406 |
PaperMtn/slack-watchman
Slack enumeration and exposed secrets detection tool
Metrics details
| Stars | 404 |
brandonprry/gray_hat_csharp_code
This repository contains full code examples from the book Gray Hat C#
Metrics details
| Stars | 397 |
BishopFox/smogcloud
Find cloud assets that no one wants exposed 🔎 ☁️
Metrics details
| Stars | 351 |
joswha/Secure-Coding-Handbook
Web Application Secure Coding Handbook resource.
Metrics details
| Stars | 346 |
cr0nx/awesome-linux-attack-forensics-purplelabs
This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.
Metrics details
| Stars | 341 |
3CORESec/MAL-CL
MAL-CL (Malicious Command-Line)
Metrics details
| Stars | 330 |
Cn33liz/StarFighters
A JavaScript and VBScript Based Empire Launcher, which runs within their own embedded PowerShell Host.
Metrics details
| Stars | 321 |
DamonMohammadbagher/ETWProcessMon2
ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
Metrics details
| Stars | 321 |
whitehatnote/BlueShell
红蓝对抗跨平台远控工具
Metrics details
| Stars | 306 |
hevnsnt/Awesome_Incident_Response
Awesome Incident Response
Metrics details
| Stars | 294 |
n0dec/MalwLess
Test Blue Team detections without running any attack.
Metrics details
| Stars | 272 |
