Skip to content
Change the repository type filter

All

    Repositories list

    • The cortex.xsoar collection includes Ansible modules to help automate the management of Palo Alto Cortex XSOAR.
      Python
      5602Updated Jul 31, 2025Jul 31, 2025
    • nviso-cti

      Public
      YARA
      54201Updated Jul 11, 2025Jul 11, 2025
    • A Magisk/KernelSU module that automatically adds user certificates to the system root CA store
      Shell
      2272k20Updated Jun 24, 2025Jun 24, 2025
    • A Frida script that disables Flutter's TLS verification
      C++
      7245910Updated May 19, 2025May 19, 2025
    • KNOCKOUT

      Public
      The tool KNOCKOUT streamlines the collection and aggregation of incident response artifacts from multiple sources, significantly saving time during critical initial access phases of Red Team exercises.
      C#
      1700Updated Apr 15, 2025Apr 15, 2025
    • cs2br-bof

      Public
      Run Cobalt Strike BOFs in Brute Ratel C4!
      C
      166800Updated Apr 15, 2025Apr 15, 2025
    • codasm

      Public
      Payload encoding utility to effectively lower payload entropy.
      Python
      1511900Updated Apr 15, 2025Apr 15, 2025
    • Monitor osquery logs and use an LLM to provide concise, user-friendly summaries of new events directly in Discord.
      Python
      0600Updated Apr 9, 2025Apr 9, 2025
    • This repository contains the demo code for the webcast organized by SANS titled "From Playbooks to Robocop: The Evolution of SOC Automation".
      Python
      1700Updated Mar 27, 2025Mar 27, 2025
    • blogposts

      Public
      A repo to house files for our blogposts on blog.nviso.eu
      C++
      177200Updated Mar 13, 2025Mar 13, 2025
    • BitSight Automation was developed to automate certain manual procedures and extract information such as ratings, assets, findings, etc. This tool also provides the possibility to collaborate with Scheduled Tasks and cronjobs.
      Python
      0901Updated May 21, 2024May 21, 2024
    • A collection of agents that use Large Language Models (LLMs) to perform tasks common on our day to day jobs in cyber security.
      Jupyter Notebook
      2014711Updated May 7, 2024May 7, 2024
    • Windows OS Hardening with PowerShell DSC
      PowerShell
      117279172Updated Nov 23, 2023Nov 23, 2023
    • IOXY

      Public
      MQTT intercepting proxy
      Go
      2013840Updated Aug 20, 2023Aug 20, 2023
    • caldera

      Public archive
      An automated adversary emulation system
      Python
      1.2k208Updated Aug 1, 2023Aug 1, 2023
    • sigma-public

      Public archive
      Generic Signature Format for SIEM Systems
      Python
      2.4k1704Updated Jul 25, 2023Jul 25, 2023
    • C#
      2511202Updated Jul 24, 2023Jul 24, 2023
    • velociraptor

      Public archive
      Digging Deeper....
      Go
      542003Updated Jul 20, 2023Jul 20, 2023
    • Images & other assets we want to statically include in documentation
      0000Updated Jun 30, 2023Jun 30, 2023
    • pyCobaltHound is an Aggressor script extension for Cobalt Strike which aims to provide a deep integration between Cobalt Strike and Bloodhound.
      Python
      2113701Updated May 25, 2023May 25, 2023
    • Quickly debug shellcode extracted during malware analysis
      C
      88200Updated May 23, 2023May 23, 2023
    • ee-outliers

      Public archive
      Open-source framework to detect outliers in Elasticsearch events
      Python
      33209294Updated May 22, 2023May 22, 2023
    • flare

      Public
      An analytical framework for network traffic and behavioral analytics
      Python
      87201Updated May 22, 2023May 22, 2023
    • An iOS app that lets you practice your Frida skills
      Swift
      2117610Updated Apr 20, 2023Apr 20, 2023
    • CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection, persistence and more, leveraging direct syscalls (SysWhispers2) to bypass EDR/AV
      C
      3423610Updated Jan 4, 2023Jan 4, 2023
    • 12200Updated Jan 2, 2023Jan 2, 2023
    • Interceptor is a kernel driver focused on tampering with EDR/AV solutions in kernel space
      C++
      1712300Updated Jan 2, 2023Jan 2, 2023
    • Repository with files for remote acquisition of files / artifacts
      PowerShell
      1100Updated Oct 5, 2022Oct 5, 2022
    • AutoIt unpacker service
      Python
      2100Updated Sep 19, 2022Sep 19, 2022
    • Simple MSG extractor AssemblyLine service
      Python
      0200Updated Sep 19, 2022Sep 19, 2022