A simple python script that generate platform-specific queries (e.g., AQL, Elasticsearch, Defender) from input lists of IP addresses, domain names, or file hashes to identify first point of contact.
A cross-platform desktop GUI tool that helps security analysts build and customize threat hunting queries for platforms like Qradar, Elastic and Defender.
This tool helps analysts quickly identify rules related to a particular service (e.g., Apache Kylin, MySQL) by scanning the msg field in alert definitions in rule sets for intrusion detection systems like Suricata and Snort.
Generate platform-specific queries (QRadar, Elastic, Defender) from IPs, domains, or hashes to speed up your threat hunting workflow.
Automate Your Way into the Attack Surface.
Lessons from automating IDS rule deployment and evaluating Stamus NDR.