Cross-platform incident response toolkit. 28 pre-built use cases in a single zero-install binary: triage, threat hunting, memory forensics, disk collection, remote operations, and Velociraptor management. Works air-gapped, with automated timeline generation.
☆154Jul 28, 2026Updated this week
Alternatives and similar repositories for vanguard
Users that are interested in vanguard are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only.☆57Updated this week
- GitHub Workflows Insights☆47Jun 27, 2026Updated last month
- ☆22Jan 7, 2026Updated 6 months ago
- DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them agai…☆36Updated this week
- An OpenAI API Compatible Honeypot Gateway☆26Mar 17, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techn…☆57Jul 5, 2026Updated 3 weeks ago
- OpenGraph Collector for Tailscale☆43Jul 9, 2026Updated 3 weeks ago
- Generate realistic synthetic security logs for cybersecurity threat hunting training and research☆198Updated this week
- Secrets scanner with a twist... this is for getting threat actor credentials from MALWARE. Acquire TA creds from FLOSS exports, memdumps…☆38Jun 19, 2026Updated last month
- Python CLI that creates GitHub repos with safe defaults — branch protection, Dependabot, secret scanning, and pre-flight security scannin…☆38Updated this week
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret …☆302Jul 27, 2026Updated last week
- Linux Persistence Detection, Hunting and Artifact Collection script☆24Jul 20, 2026Updated 2 weeks ago
- Interactive PowerShell framework for testing WMI, COM, LOLBAS, and persistence techniques☆130Dec 28, 2025Updated 7 months ago
- Janus analyzes C2 telemetry to surface failure patterns, operator friction, and automation opportunities across engagements.☆56Jun 23, 2026Updated last month
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Hunt Smarter, Hunt Harder☆199Mar 14, 2026Updated 4 months ago
- A swiss-knife MCP server for analysing PCAP files☆73Apr 28, 2026Updated 3 months ago
- Your Browser-based EVTX Companion☆123Jul 21, 2026Updated last week
- An awesome collection of articles, papers, conferences, guides, and tools relating to deception in cybersecurity.☆129Jun 10, 2026Updated last month
- PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via …☆167Jan 25, 2026Updated 6 months ago
- ☆24Mar 4, 2025Updated last year
- A sysmon configuration designed for monitoring RMM solutions from the LOLRMM framework on the OS Microsoft Windows. 10/11☆33Feb 17, 2026Updated 5 months ago
- Velociraptor Server hosted in Azure App Service☆59Jun 4, 2025Updated last year
- ⚡ AI-powered cybersecurity CLI tool for Kali Linux | Ethical hacking | Penetration testing | Bug bounty☆39May 20, 2026Updated 2 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.☆20Jan 22, 2026Updated 6 months ago
- Run TTPs, with AI!☆140Feb 23, 2026Updated 5 months ago
- Open source HIDS tailored for Microsoft Windows and Active Directory☆31Jul 23, 2026Updated last week
- Threat Hunting queries of multiple platforms☆77Jul 15, 2026Updated 2 weeks ago
- Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSO…☆445Updated this week
- MCP to help Defenders Detection Engineer Harder and Smarter☆467Jun 16, 2026Updated last month
- AppLocker Policy Generator☆26Aug 25, 2025Updated 11 months ago
- ☆21Jul 13, 2026Updated 3 weeks ago
- Tool created for Red Team to test default credentials on SSH and WinRM and then execute scripts with those credentials before the passwor…☆41May 7, 2023Updated 3 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- ☆79May 8, 2026Updated 2 months ago
- Falco-powered policy and visibility layer for AI coding agents☆188Jul 27, 2026Updated last week
- HoneyWire: The Open-Source, Unlimited Deception Platform. Turn any Linux machine into an enterprise-grade canary in 60 seconds.☆98Jul 19, 2026Updated 2 weeks ago
- KustoHawk is a lightweight incident triage and response tool designed for effective incident response in Microsoft Defender XDR and Micro…☆158Apr 1, 2026Updated 4 months ago
- how to strangle threats☆58Updated this week
- A Kubernetes Forensic Collection Framework for Azure Kubernetes Service☆43Feb 9, 2026Updated 5 months ago
- A curated collection of DFIR skills and workflows for InfoSec practitioners.☆319May 14, 2026Updated 2 months ago