
Projects
Open source tools for threat detection and security research.
33 projects


evtx-baseline
activeA repository hosting example goodware evtx logs containing sample software installation and basic user interaction

go-elasticsearch
activeSimple ElasticSearch API for Golang
nextron-helper-scripts
activePublic tools, scripts or code snippets that can help when working with our products



scanning-containers
activeGuides and scripts for different uses cases regarding scanning containers with THOR
scanning-sql-databases
activeGuides and scripts for different uses cases regarding scanning SQL databases with THOR
sysmon-config
activeSysmon configuration file template with default high-quality event tracing

TA-aurora
activeSplunk Technology-AddOn for Aurora Sigma-Based EDR Agent. It helps parse and configure the necessary inputs to neatly consume Aurora EDR Agent Alerts into Splunk.
thor-microsoft-defender-guide
activeTHOR Integration Guide for Microsoft Defender ATP
thor2timesketch
activethor2ts – A utility to convert THOR logs to Timesketch’s required format.

