top of page

All Posts

Talfor ShareWatch - a free, open-source DLP tripwire for Windows file shares.

🔔 Alerts the moment a sensitive folder is accessed 🌐 Logs the source IP, hostname, and username of every access 👁️ Catches reads and opens - not just modifications (FileSystemWatcher alone can't do this; Security Event 5145 can) 🧹 Filters the noise so every log line means something No agents. No licensing. No heavy DLP suite. Just Windows doing what it was always capable of, properly configured. Built at Talfor for insider-threat monitoring and evidence-grade access loggi

RITA - An open source framework for network traffic analysis.

The framework ingests Zeek Logs in TSV or JSON format, and currently supports the following major features: Beaconing Detection: Search for signs of beaconing behavior in and out of your network. Long Connection Detection : Easily see connections that have communicated for long periods of time. DNS Tunneling Detection : Search for signs of DNS based covert channels. Threat Intel Feed Checking : Query threat intel feeds to search for suspicious domains and hosts. Check out t

Untitled Goose Tool

Much useful Incident Response (IR) tool released by CISA to run a full investigation against a customer’s Azure Active Directory...

Magnet RESPONSE tool

The acquisition of volatile data in the IR process is very important and Incident Responders used to execute separate tools and commands...

WinPMEM free RAM capture tool

Adding to the list of free RAM capture tools -WinPMEM — an open-source memory acquisition tool. Download from https://lnkd.in/g8eUvPM8...

ETL File Analysis

There are events that carry information about shell Items, network shares, apps that require privileges, RunKey information etc.; When...

bottom of page