Blueteam Open Source Projects

Browse 103 Blueteam open source projects, ranked by GitHub stars. Find the most popular Blueteam tools and libraries.

Share your experience:✍️ Write a Post❓ Ask a Question
1-60 of 103 projects
16,843 stars

laramies/theHarvester

E-mails, subdomains and names Harvester - OSINT

Metrics details
Stars16,843
13,464 stars

GTFOBins/GTFOBins.github.io

GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.

Metrics details
Stars13,464
8,694 stars

LOLBAS-Project/LOLBAS

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

Metrics details
Stars8,694
7,612 stars

yaklang/yakit

Cyber Security ALL-IN-ONE Platform

Metrics details
Stars7,612
6,678 stars

ihebski/DefaultCreds-cheat-sheet

One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️

Metrics details
Stars6,678
6,469 stars

decalage2/awesome-security-hardening

A collection of awesome security hardening guides, tools and other resources

Metrics details
Stars6,469
5,978 stars

rmusser01/Infosec_Reference

An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.

Metrics details
Stars5,978
5,719 stars

madhuakula/kubernetes-goat

Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀

Metrics details
Stars5,719
5,702 stars

ffffffff0x/1earn

ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup

Metrics details
Stars5,702
4,246 stars

A-poc/BlueTeam-Tools

Tools and Techniques for Blue Team / Incident Response

Metrics details
Stars4,246
3,970 stars

snooppr/snoop

Snoop — инструмент разведки на основе открытых данных (OSINT world)

Metrics details
Stars3,970
3,603 stars

WithSecureLabs/chainsaw

Rapidly Search and Hunt through Windows Forensic Artefacts

Metrics details
Stars3,603
3,193 stars

JPCERTCC/LogonTracer

Investigate malicious Windows logon by visualizing and analyzing Windows event log

Metrics details
Stars3,193
2,879 stars

opsdisk/the_cyber_plumbers_handbook

Free copy of The Cyber Plumber's Handbook - The definitive guide to Secure Shell (SSH) tunneling, port redirection, and bending traffic like a boss.

Metrics details
Stars2,879
2,637 stars

0x6d69636b/windows_hardening

HardeningKitty and Windows Hardening Settings

Metrics details
Stars2,637
2,629 stars

Mr-xn/RedTeam_BlueTeam_HW

红蓝对抗以及护网相关工具和资料,内存shellcode(cs+msf)和内存马查杀工具

Metrics details
Stars2,629
2,293 stars

bigb0sss/RedTeam-OffensiveSecurity

Tools & Interesting Things for RedTeam Ops

Metrics details
Stars2,293
2,188 stars

lkarlslund/Adalanche

Attack Graph Visualizer and Explorer (Active Directory) ...Who's *really* Domain Admin?

Metrics details
Stars2,188
2,075 stars

api0cradle/UltimateAppLockerByPassList

The goal of this repository is to document the most common techniques to bypass AppLocker.

Metrics details
Stars2,075
1,794 stars

scipag/HardeningKitty

HardeningKitty - Checks and hardens your Windows configuration

Metrics details
Stars1,794
1,756 stars

Purp1eW0lf/Blue-Team-Notes

You didn't think I'd go and leave the blue team out, right?

Metrics details
Stars1,756
1,751 stars

mthcht/awesome-lists

Awesome Security lists for SOC/CERT/CTI

Metrics details
Stars1,751
1,721 stars

Bert-JanP/Hunting-Queries-Detection-Rules

KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.

Metrics details
Stars1,721
1,691 stars

WADComs/WADComs.github.io

WADComs is an interactive cheat sheet, containing a curated list of offensive security tools and their respective commands, to be used against Windows/AD environments.

Metrics details
Stars1,691
1,613 stars

api0cradle/LOLBAS

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

Metrics details
Stars1,613
1,539 stars

xiecat/goblin

一款适用于红蓝对抗中的仿真钓鱼系统

Metrics details
Stars1,539
1,299 stars

PlumHound/PlumHound

Bloodhound Reporting for Blue and Purple Teams

Metrics details
Stars1,299
1,163 stars

NH-RED-TEAM/RustHound

Active Directory data ingestor for BloodHound Legacy written in Rust. 🦀

Metrics details
Stars1,163
953 stars

cfalta/MicrosoftWontFixList

A list of vulnerabilities or design flaws that Microsoft does not intend to fix. Since the number is growing, I decided to make a list. This list covers only vulnerabilities that came up in July 2021 (and SpoolSample ;-))

Metrics details
Stars953
916 stars

FalconForceTeam/FalconFriday

Hunting queries and detections

Metrics details
Stars916
808 stars

scythe-io/purple-team-exercise-framework

Purple Team Exercise Framework

Metrics details
Stars808
780 stars

emtunc/SlackPirate

Slack Enumeration and Extraction Tool - extract sensitive information from a Slack Workspace

Metrics details
Stars780
777 stars

bluecapesecurity/PWF

Practical Windows Forensics Training

Metrics details
Stars777
750 stars

cyberark/PipeViewer

A tool that shows detailed information about named pipes in Windows

Metrics details
Stars750
732 stars

Zeus-Labs/ZeusCloud

Open Source Cloud Security

Metrics details
Stars732
684 stars

enomothem/Whoamifuck

用于Linux应急响应,快速排查异常用户登录情况和入侵信息排查,准确定位溯源时间线,高效辅助还原攻击链。

Metrics details
Stars684
670 stars

0xDanielLopez/TweetFeed

TweetFeed collects Indicators of Compromise (IOCs) shared by the infosec community at Twitter. Here you will find malicious URLs, domains, IPs, and SHA256/MD5 hashes.

Metrics details
Stars670
666 stars

mthcht/ThreatHunting-Keywords

Awesome list of keywords and artifacts for Threat Hunting sessions

Metrics details
Stars666
654 stars

auth0/repo-supervisor

Scan your code for security misconfiguration, search for passwords and secrets. :mag:

Metrics details
Stars654
612 stars

ffffffff0x/Pentest101

一些关于渗透测试的Tips

Metrics details
Stars612
604 stars

activecm/rita

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Metrics details
Stars604
593 stars

loseys/Oblivion

Data leak checker & OSINT Tool

Metrics details
Stars593
577 stars

LewisArdern/bXSS

bXSS is a utility which can be used by bug hunters and organizations to identify Blind Cross-Site Scripting.

Metrics details
Stars577
567 stars

WiPi-Hunter/PiDense

🍓📡🍍Monitor illegal wireless network activities. (Fake Access Points), (WiFi Threats: KARMA Attacks, WiFi Pineapple, Similar SSID, OPN Network Density etc.)

Metrics details
Stars567
542 stars

infosecB/LOOBins

Living Off the Orchard: macOS Binaries (LOOBins) is designed to provide detailed information on various built-in "living off the land" macOS binaries and how they can be used by threat actors for malicious purposes.

Metrics details
Stars542
488 stars

idnahacks/GoodHound

Uses Sharphound, Bloodhound and Neo4j to produce an actionable list of attack paths for targeted remediation.

Metrics details
Stars488
472 stars

redeye-framework/Redeye

Redeye is a tool intended to help you manage your data during a pentest operation

Metrics details
Stars472
461 stars

burpheart/koko-moni

一个基于网络空间搜索引擎的攻击面管理平台,可定时进行资产信息爬取,及时发现新增资产,本项目聚合了 Fofa、Hunter、Quake、Zoomeye 和 Threatbook 的数据源,并对获取到的数据进行去重与清洗

Metrics details
Stars461
406 stars

cyberark/RPCMon

RPC Monitor tool based on Event Tracing for Windows

Metrics details
Stars406
404 stars

PaperMtn/slack-watchman

Slack enumeration and exposed secrets detection tool

Metrics details
Stars404
397 stars

brandonprry/gray_hat_csharp_code

This repository contains full code examples from the book Gray Hat C#

Metrics details
Stars397
351 stars

BishopFox/smogcloud

Find cloud assets that no one wants exposed 🔎 ☁️

Metrics details
Stars351
346 stars

joswha/Secure-Coding-Handbook

Web Application Secure Coding Handbook resource.

Metrics details
Stars346
341 stars

cr0nx/awesome-linux-attack-forensics-purplelabs

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Metrics details
Stars341
330 stars

3CORESec/MAL-CL

MAL-CL (Malicious Command-Line)

Metrics details
Stars330
321 stars

Cn33liz/StarFighters

A JavaScript and VBScript Based Empire Launcher, which runs within their own embedded PowerShell Host.

Metrics details
Stars321
321 stars

DamonMohammadbagher/ETWProcessMon2

ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.

Metrics details
Stars321
306 stars

whitehatnote/BlueShell

红蓝对抗跨平台远控工具

Metrics details
Stars306
294 stars

hevnsnt/Awesome_Incident_Response

Awesome Incident Response

Metrics details
Stars294
272 stars

n0dec/MalwLess

Test Blue Team detections without running any attack.

Metrics details
Stars272
1-60 of 103 projects
Get A Weekly Email With Trending Blueteam Projects
Stay updated on Blueteam plus related topics you pick below.

Copyright 2018-2026 Awesome Open Source.  All rights reserved.