A collection of awesome security hardening guides, tools and other resources
Blue Team GitHub Repositories
Explore popular GitHub repositories tagged “blue-team”.
Compare stars, forks, and programming language using the same GitStar view as GitHub Trending.
Trending Repositories
Adversarial Robustness Toolbox (ART) - Python Library for Machine Learning Security - Evasion, Poisoning, Extraction, Inference - Red and Blue Teams
:computer:🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.
Tools and Techniques for Blue Team / Incident Response
A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.
A FREE Windows C development course where we will learn the Win32API and reverse engineer each step utilizing IDA Free in both an x86 and x64 environment.
BigBountyRecon tool utilises 58 different techniques using various Google dorks and open source tools to expedite the process of initial reconnaissance on the target organisation.
An Active Defense and EDR software to empower Blue Teams
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.
openSquat is an open-source tool that detects look-alike domains impersonating your brand, by scanning newly registered domains daily.
网络安全 · 攻防对抗 · 蓝队清单,中文版
Security automation with n8n ideas: 100+ Red/Blue/AppSec workflows, integrations, and ready-to-run playbooks.
🦄🔒 Awesome list of secrets in environment variables 🖥️
Security Auditor Utility for GraphQL APIs
Krawl is a customizable, lightweight, cloud-native web deception server and anti-crawler that creates fake web applications with low-hanging vulnerabilities using realistic, randomly generated decoy data and AI-generated HTML templates.
Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
AWS CloudSaga - Simulate security events in AWS
Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.
Slack enumeration and exposed secrets detection tool
PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.
Respounder detects presence of responder in the network.
15-stage Windows malware development & analysis course in Rust. Red team builds it, blue team detects it. All 15 binaries achieved 0/76 on VirusTotal.
Assisted Log Enabler for AWS - Find AWS resources that are not logging, and turn them on.
Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compatible with VMware and Hyper-V.
Detecting ATT&CK techniques & tactics for Linux
Give your AI coding agent a personality. Composable persona + style + skills for Claude Code, Codex, Gemini CLI & OpenClaw. Ships Tech Persona Card v1.0 spec.
A tool designed to hunt for Phishing Kit source code
Browser Protector against various stealers, written in C# & C/C++.
This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to extract juicy information such as LAPS passwords or any sensitive information on the screen. Blue Team member can reconstruct PNG files to see what an attacker did on a compromised host. It is extremely useful for a forensics team to extract timestamps after an attack on a host to collect evidences and perform further analysis.