Skip to content
Change the repository type filter

All

    Repositories list

    • Detection-and-Hunting-Queries

      Public
      This repository contains detection and threat hunting queries created by NVISO’s CSIRT and SOC teams.
      MIT License
      01700Updated May 14, 2026May 14, 2026
    • A Frida script that disables Flutter's TLS verification
      C++
      9762220Updated May 4, 2026May 4, 2026
    • IOXY

      Public
      MQTT intercepting proxy
      Go
      GNU General Public License v3.0
      2214253Updated Dec 5, 2025Dec 5, 2025
    • cortex.xsoar

      Public
      The cortex.xsoar collection includes Ansible modules to help automate the management of Palo Alto Cortex XSOAR.
      Python
      GNU General Public License v3.0
      7601Updated Aug 5, 2025Aug 5, 2025
    • nviso-cti

      Public
      YARA
      54401Updated Jul 11, 2025Jul 11, 2025
    • A Magisk/KernelSU module that automatically adds user certificates to the system root CA store
      Shell
      2612.5k100Updated Jun 24, 2025Jun 24, 2025
    • KNOCKOUT

      Public
      The tool KNOCKOUT streamlines the collection and aggregation of incident response artifacts from multiple sources, significantly saving time during critical ini…
      C#
      MIT License
      2700Updated Apr 15, 2025Apr 15, 2025
    • cs2br-bof

      Public
      Run Cobalt Strike BOFs in Brute Ratel C4!
      C
      BSD 3-Clause "New" or "Revised" License
      178800Updated Apr 15, 2025Apr 15, 2025
    • codasm

      Public
      Payload encoding utility to effectively lower payload entropy.
      Python
      MIT License
      2013000Updated Apr 15, 2025Apr 15, 2025
    • Monitor osquery logs and use an LLM to provide concise, user-friendly summaries of new events directly in Discord.
      Python
      GNU General Public License v3.0
      1600Updated Apr 9, 2025Apr 9, 2025
    • This repository contains the demo code for the webcast organized by SANS titled "From Playbooks to Robocop: The Evolution of SOC Automation".
      Python
      2900Updated Mar 27, 2025Mar 27, 2025
    • blogposts

      Public
      A repo to house files for our blogposts on blog.nviso.eu
      C++
      177500Updated Mar 13, 2025Mar 13, 2025
    • BitSight Automation was developed to automate certain manual procedures and extract information such as ratings, assets, findings, etc. This tool also provides …
      Python
      GNU General Public License v3.0
      01001Updated May 21, 2024May 21, 2024
    • A collection of agents that use Large Language Models (LLMs) to perform tasks common on our day to day jobs in cyber security.
      Jupyter Notebook
      6935911Updated May 7, 2024May 7, 2024
    • Windows OS Hardening with PowerShell DSC
      PowerShell
      GNU General Public License v3.0
      113289172Updated Nov 23, 2023Nov 23, 2023
    • caldera

      Public archive
      An automated adversary emulation system
      Python
      Apache License 2.0
      1.3k308Updated Aug 1, 2023Aug 1, 2023
    • sigma-public

      Public archive
      Generic Signature Format for SIEM Systems
      Python
      2.6k1804Updated Jul 25, 2023Jul 25, 2023
    • C#
      2511212Updated Jul 24, 2023Jul 24, 2023
    • velociraptor

      Public archive
      Digging Deeper....
      Go
      Other
      616103Updated Jul 20, 2023Jul 20, 2023
    • Images & other assets we want to statically include in documentation
      0000Updated Jun 30, 2023Jun 30, 2023
    • pyCobaltHound is an Aggressor script extension for Cobalt Strike which aims to provide a deep integration between Cobalt Strike and Bloodhound.
      Python
      GNU General Public License v3.0
      1913501Updated May 25, 2023May 25, 2023
    • Quickly debug shellcode extracted during malware analysis
      C
      MIT License
      87400Updated May 23, 2023May 23, 2023
    • ee-outliers

      Public archive
      Open-source framework to detect outliers in Elasticsearch events
      Python
      GNU General Public License v3.0
      33204294Updated May 22, 2023May 22, 2023
    • flare

      Public
      An analytical framework for network traffic and behavioral analytics
      Python
      MIT License
      88301Updated May 22, 2023May 22, 2023
    • An iOS app that lets you practice your Frida skills
      Swift
      2319810Updated Apr 20, 2023Apr 20, 2023
    • CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection, persistence and mo…
      C
      MIT License
      3524110Updated Jan 4, 2023Jan 4, 2023
    • 12300Updated Jan 2, 2023Jan 2, 2023
    • Interceptor is a kernel driver focused on tampering with EDR/AV solutions in kernel space
      C++
      GNU General Public License v3.0
      1913500Updated Jan 2, 2023Jan 2, 2023
    • Repository with files for remote acquisition of files / artifacts
      PowerShell
      GNU General Public License v3.0
      1100Updated Oct 5, 2022Oct 5, 2022
    • AutoIt unpacker service
      Python
      MIT License
      1100Updated Sep 19, 2022Sep 19, 2022
    ProTip! When viewing an organization's repositories, you can use the props. filter to filter by custom property.