A tool collection for filtering and visualizing logon events. Designed to help answering the "Cotton Eye Joe" question (Where did you come from where did you go) in Security Incidents and Threat Hunts
☆187Jul 23, 2026Updated this week
Alternatives and similar repositories for Blauhaunt
Users that are interested in Blauhaunt are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆11Jun 12, 2023Updated 3 years ago
- ShellSweeping the evil.☆183Updated this week
- ☆209May 10, 2026Updated 2 months ago
- A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID☆666Jul 6, 2026Updated 3 weeks ago
- A centralized and enhanced memory analysis platform☆536Jul 21, 2026Updated last week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- The purpose of this project is to publish and maintain the deployment PowerShell script that automates deployments for Active Directory C…☆266Nov 24, 2023Updated 2 years ago
- DFIQ is a collection of investigative questions and the approaches for answering them☆310Mar 10, 2026Updated 4 months ago
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆34Jun 27, 2025Updated last year
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆94Aug 30, 2024Updated last year
- ☆570Mar 28, 2024Updated 2 years ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆93Mar 11, 2026Updated 4 months ago
- Documentation and scripts to properly enable Windows event logs.☆712Oct 3, 2025Updated 9 months ago
- MDE relies on some of the Audit settings to be enabled☆101Jul 15, 2022Updated 4 years ago
- Modular web-application honeypot platform built using go and gin☆63May 8, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A repository to share publicly available Velociraptor detection content☆205Updated this week
- ☆84Feb 4, 2026Updated 5 months ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆89Feb 9, 2025Updated last year
- Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detection…☆868Jan 20, 2022Updated 4 years ago
- Live Feed of C2 servers, tools, and botnets☆777Apr 13, 2026Updated 3 months ago
- FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is de…☆824Apr 18, 2026Updated 3 months ago
- Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.☆3,269Updated this week
- Awesome list of keywords and artifacts for Threat Hunting sessions☆669Aug 4, 2025Updated 11 months ago
- UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It …☆1,416Jul 1, 2026Updated 3 weeks ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifa…☆660Jul 14, 2026Updated 2 weeks ago
- ☆58Dec 13, 2025Updated 7 months ago
- An evolving repository of CloudTrail events with detailed descriptions, MITRE ATT&CK insights, real-world incidents, references and secur…☆174Jul 12, 2026Updated 2 weeks ago
- PoC for using MS Windows printers for persistence / command and control via Internet Printing☆155May 3, 2024Updated 2 years ago
- ☆33Feb 26, 2022Updated 4 years ago
- ☆84Nov 21, 2024Updated last year
- The MAGIC tool is a wrapper around the Microsoft Graph Python SDK, designed to download incident response-relevant data from M365 environ…☆35Apr 13, 2026Updated 3 months ago
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆837May 30, 2026Updated last month
- ☆267Jun 7, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆16May 3, 2024Updated 2 years ago
- ☆93Jul 30, 2025Updated 11 months ago
- BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse en…☆513Updated this week
- WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)☆775Feb 3, 2023Updated 3 years ago
- ☆130Feb 19, 2026Updated 5 months ago
- Hundred Days of Yara Challenge☆12Jun 21, 2022Updated 4 years ago
- Canary Detection☆199Oct 20, 2025Updated 9 months ago