Build AI-powered security tools. 50+ hands-on labs covering ML, LLMs, RAG, threat detection, DFIR, and red teaming. Includes Colab notebooks, Docker environment, and CTF challenges.
☆157Jun 1, 2026Updated last month
Alternatives and similar repositories for ai_for_the_win
Users that are interested in ai_for_the_win are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Automated n8n workflow for ransomware threat monitoring using ransomware.live API and Claude AI — companion to the SANS Ransomware Intell…☆22Apr 15, 2026Updated 3 months ago
- SOC-in-a-Box for AI purple teaming☆19Updated this week
- A DFIR Incident Response AI bot using local Ollama LLM to derrive automated findings from logs☆16Jan 17, 2026Updated 6 months ago
- A curated collection of DFIR skills and workflows for InfoSec practitioners.☆321May 14, 2026Updated 2 months ago
- Curated resources, research, and tools for securing AI systems☆826Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Single-file desktop GUI for searching, browsing, and analyzing SQLite databases. Python + tkinter. No install required.☆23Apr 25, 2026Updated 2 months ago
- A Docker lab integrating Splunk SIEM with Ollama LLM via MCP for AI security operations. Features Promptfoo OWASP evaluation, TA-ollama a…☆32Jul 3, 2026Updated 2 weeks ago
- An automated pipeline that leverages LLM's meta-learning capability to iteratively design and refine red-teaming systems without human in…☆30May 24, 2026Updated last month
- A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concret…☆57Mar 5, 2026Updated 4 months ago
- An Obsidian-Based Second Brain for CyberSecurity Analysts and Professionals☆59Feb 18, 2026Updated 5 months ago
- Pyside6 implementation of YaraXGUI☆28May 19, 2026Updated 2 months ago
- Shattering the 1:10 barrier. A high-velocity alternative to Plaso for the modern IR landscape☆16Jul 6, 2026Updated 2 weeks ago
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret …☆296Jun 6, 2026Updated last month
- Powershell Scripts to work on Crowdstrike Falcon that pull back raw data relevant to forensic investigation☆23Dec 18, 2024Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A comprehensive repository for malware analysis and threat intelligence, including Cobalt Strike Beacon configurations, YARA rules, IOCs,…☆18Mar 6, 2026Updated 4 months ago
- AI-Driven Threat Modeling & Attack Tree Generation with MITRE ATT&CK Integration☆63Updated this week
- Cyber Threat Intelligence☆82Dec 7, 2025Updated 7 months ago
- Offline AI Security Assistant for Air-Gapped Pentesting☆84Apr 19, 2026Updated 3 months ago
- ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.☆334Updated this week
- Agentic CVE → Docker environment builder: given a CVE ID, builds and verifies a Docker environment running the affected application at it…☆25Jul 12, 2026Updated last week
- PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.☆23Mar 1, 2026Updated 4 months ago
- geolocate ip addresses in IIS logs☆21May 10, 2026Updated 2 months ago
- AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone —…☆942Jun 24, 2026Updated 3 weeks ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Automatic Microsoft Sentinel Deployment☆16Apr 1, 2025Updated last year
- JSHawk is a powerful, context-aware JavaScript security scanner that hunts for exposed credentials, API keys, and sensitive information i…☆17Apr 13, 2026Updated 3 months ago
- MCP to help Defenders Detection Engineer Harder and Smarter☆462Jun 16, 2026Updated last month
- Automatic/Custom Destinations & LNK (MS-SHLLINK) Browser☆49Jun 3, 2026Updated last month
- Encrypted command‑and‑control (C2) research framework for cybersecurity education, red team labs, and secure client‑server communication …☆31Mar 15, 2026Updated 4 months ago
- Automate forensic traige package collection and evidence parsing with KAPE and Crowdstrike☆15Mar 5, 2022Updated 4 years ago
- A collection of PowerShell scripts for analyzing macOS Forensic Artifacts☆33Mar 16, 2026Updated 4 months ago
- A Shodan-based tool to discover publicly exposed Ollama instances and list available LLM models.☆22May 27, 2025Updated last year
- AI Red Team Operations Console☆16Jul 5, 2026Updated 2 weeks ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- CTI Expert — Cyber Threat Intelligence & OSINT analysis skill for Claude Code. 67+ commands, 35 techniques, no API keys required.☆255Updated this week
- This is the repository for AI for SOC short video series☆19Sep 12, 2025Updated 10 months ago
- Contains compiled binaries of Volatility☆37May 18, 2025Updated last year
- Comprehensive security and best practices guide for using Claude Code safely and effectively☆16Mar 29, 2026Updated 3 months ago
- world's first Opensource fully Autonomous AI Security Engineer☆244Nov 18, 2025Updated 8 months ago
- A repo to hold KQL queries as part of my 100 days of KQL effort.☆19Apr 17, 2026Updated 3 months ago
- Automated pentest report writing and generation using DOCX templates and markdown.☆27Apr 1, 2025Updated last year