Reverse engineering and pentesting for Android applications
HFish is a distributed honeypot system and network intrusion detection tool designed to deploy decoy services and nodes to detect and analyze attacker behavior. It functions as a deceptive asset orchestrator that simulates enterprise services and configures custom baits to lure network intruders. The system utilizes a server-client architecture to manage distributed nodes across different platforms, allowing for centralized control of telemetry collection and decoy deployment. It incorporates cloud-based traffic routing to redirect suspicious network activity into managed decoy environments f
Security Onion is a security information and event management platform and network security monitoring suite. It functions as an intrusion detection system and a network traffic analysis tool designed to identify malicious activity and network intrusions through signature-based detection and host-based monitoring. The platform integrates a security case management system to organize investigations by tracking detections and grouping related security events. It provides capabilities for full packet capture, network metadata extraction, and the collection and indexing of security logs from dive
Seatbelt is a C# offensive security framework and host security auditor designed to perform endpoint surveys on Windows systems. It functions as a modular tool for identifying vulnerabilities, misconfigurations, and security-relevant artifacts on both local and remote hosts. The project distinguishes itself through a module-based check system that allows for the integration of custom security command units. It features a security event log parser to track logon and process activity, alongside a credential extraction utility for gathering browser history, saved passwords, and cloud credentials
Adversary tradecraft detection, protection, and hunting
The main features of rabbitstack/fibratus are: Security Logging and SIEM, Forensics Analysis, Honeypot Management, Reverse Engineering, Security and Auditing, Windows Evidence Collection, Windows Security Utilities.
Open-source alternatives to rabbitstack/fibratus include: androguard/androguard — Reverse engineering and pentesting for Android applications. hacklcx/hfish — HFish is a distributed honeypot system and network intrusion detection tool designed to deploy decoy services and… security-onion-solutions/securityonion — Security Onion is a security information and event management platform and network security monitoring suite. It… ionuttbara/windows-defender-remover — This project is a Windows security removal tool designed to permanently disable and delete antivirus services and… ghostpack/seatbelt — Seatbelt is a C# offensive security framework and host security auditor designed to perform endpoint surveys on… telekom-security/tpotce — T-Pot is a multi-honeypot platform and threat intelligence framework that deploys a collection of containerized decoy…