Skip to main content

:computer:🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.

5.3k
GitHub Stars
233
Curated Resources
19
Categories
5 hours ago
Last Refreshed
Automation and ConventionCloud platform securityCommunications security (COMSEC)DevSecOpsHoneypotsHost-based toolsIdentity and AuthN/AuthZIncident Response toolsNetwork perimeter defensesOperating System distributionsPhishing awareness and reportingPreparedness training and wargamingSecurity configurationsSecurity monitoringThreat intelligenceTor Onion service defensesTransport-layer defensesmacOS-based defensesWindows-based defenses

Use this list with your AI agent

Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:

"Show me active directory resources from awesome-cybersecurity-blueteam"

Installation instructions →

What's inside

Cloud platform security

  • Aaia

    Helps in visualizing AWS IAM and Organizations in a graph format with help of Neo4j.

  • certificate-expiry-monitorKubernetes

    Utility that exposes the expiry of TLS certificates as Prometheus metrics.

  • ConsulService meshes

    Solution to connect and configure applications across dynamic, distributed infrastructure and, with Consul Connect, enabling secure service-to-service communication with automatic TLS encryption and identity-based authorization.

  • CortexDistributed monitoring

    Provides horizontally scalable, highly available, multi-tenant, long term storage for Prometheus.

  • Falco

    Behavioral activity monitor designed to detect anomalous activity in containerized applications, hosts, and network packet flows by auditing the Linux kernel and enriched by runtime data such as Kubernetes metrics.

  • gVisor

    Application kernel, written in Go, that implements a substantial portion of the Linux system surface to provide an isolation boundary between the application and the host kernel.

Windows-based defenses

  • Active Directory Control PathsActive Directory

    Visualize and graph Active Directory permission configs ("control relations") to audit questions such as "Who can read the CEO's email?" and similar.

  • CobaltStrikeScan

    Scan files or process memory for Cobalt Strike beacons and parse their configuration.

  • HardenTools

    Utility that disables a number of risky Windows features.

  • NotRuler

    Detect both client-side rules and VBScript enabled forms used by the

  • PingCastleActive Directory

    Active Directory vulnerability detection and reporting tool.

  • PlumHoundActive Directory

    More effectively use BloodHoundAD in continual security life-cycles by utilizing its pathfinding engine to identify Active Directory security vulnerabilities.

Security monitoring

  • AlienVault OSSIMSecurity Information and Event Management (SIEM)

    Single-server open source SIEM platform featuring asset discovery, asset inventorying, behavioral monitoring, and event correlation, driven by AlienVault Open Threat Exchange (OTX).

  • ArkimeNetwork Security Monitoring (NSM)

    Augments your current security infrastructure to store and index network traffic in standard PCAP format, providing fast, indexed access.

  • ChopShopNetwork Security Monitoring (NSM)

    Framework to aid analysts in the creation and execution of pynids-based decoders and detectors of APT tradecraft.

  • CimSweepThreat hunting

    Suite of CIM/WMI-based tools enabling remote incident response and hunting operations across all versions of Windows.

  • Crossfeed

    Continuously enumerates and monitors an organization’s public-facing attack surface in order to discover assets and flag potential security flaws.

  • DeepBlueCLIThreat hunting

    PowerShell module for hunt teaming via Windows Event logs.

DevSecOps

  • AllStarPolicy enforcement

    GitHub App installed on organizations or repositories to set and enforce security policies.

  • AtherisFuzzing

    Coverage-guided Python fuzzing engine based off of libFuzzer that supports fuzzing of Python code but also native extensions written for CPython.

  • Bane

    Custom and better AppArmor profile generator for Docker containers.

  • BlackBox

    Safely store secrets in Git/Mercurial/Subversion by encrypting them "at rest" using GnuPG.

  • Checkov

    Static analysis for Terraform (infrastructure as code) to help detect CIS policy violations and prevent cloud security misconfiguration.

  • Chef InSpecCompliance testing and reporting

    Language for describing security and compliance rules, which become automated tests that can be run against IT infrastructures to discover and report on non-compliance.

Automation and Convention

  • Ansible Lockdown

    Curated collection of information security themed Ansible roles that are both vetted and actively maintained.

  • censys-pythonCode libraries and bindings

    Python wrapper to the Censys REST API.

  • Clevis

    Plugable framework for automated decryption, often used as a Tang client.

  • Dev-Sec.io

    Server hardening framework providing Ansible, Chef, and Puppet implementations of various baseline security configurations.

  • DShell

    Extensible network forensic analysis framework written in Python that enables rapid development of plugins to support the dissection of network packet captures.

  • libcrafterCode libraries and bindings

    High level C++ network packet sniffing and crafting library.

Preparedness training and wargaming

  • APTSimulator

    Toolset to make a system look as if it was the victim of an APT attack.

  • Atomic Red Team

    Library of simple, automatable tests to execute for testing security controls.

  • BadBlood

    Fills a test (non-production) Windows Domain with data that enables security analysts and engineers to practice using tools to gain an understanding and prescribe to securing Active Directory.

  • Caldera

    Scalable, automated, and extensible adversary emulation platform developed by MITRE.

  • Drool

    Replay DNS traffic from packet capture files and send it to a specified server, such as for simulating DDoS attacks on the DNS and measuring normal DNS querying.

  • DumpsterFire

    Modular, menu-driven, cross-platform tool for building repeatable, time-delayed, distributed security events for Blue Team drills and sensor/alert mapping.

Host-based tools

  • Artillery

    Combination honeypot, filesystem monitor, and alerting system designed to protect Linux and Windows operating systems.

  • BubblewrapSandboxes

    Sandboxing tool for use by unprivileged Linux users capable of restricting access to parts of the operating system or user data.

  • chkrootkit

    Locally checks for signs of a rootkit on GNU/Linux systems.

  • Crowd Inspect

    Free tool for Windows systems aimed to alert you to the presence of malware that may be communicating over the network.

  • DangerzoneSandboxes

    Take potentially dangerous PDFs, office documents, or images and convert them to a safe PDF.

  • Fail2ban

    Intrusion prevention software framework that protects computer servers from brute-force attacks.

Threat intelligence

  • AttackerKB

    Free and public crowdsourced vulnerability assessment platform to help prioritize high-risk patch application and combat vulnerability fatigue.

  • DATA

    Credential phish analysis and automation tool that can accept suspected phishing URLs directly or trigger on observed network traffic containing such a URL.

  • ESET's Malware IoCsThreat signature packages and collections

    Indicators of Compromises (IOCs) derived from ESET's various investigations.

  • FireEye's Red Team Tool CountermeasuresThreat signature packages and collections

    Collection of Snort and YARA rules to detect attacks carried out with FireEye's own Red Team tools, first released after FireEye disclosed a breach in December 2020.

  • FireEye's Sunburst CountermeasuresThreat signature packages and collections

    Collection of IoC in various languages for detecting backdoored SolarWinds Orion NMS activities and related vulnerabilities.

  • Forager

    Multi-threaded threat intelligence gathering built with Python3 featuring simple text-based configuration and data storage for ease of use and data portability.

Showing a sample of 233 resources. View the full list on GitHub →