• Kansa

    Kansa, also known as “Invoke-Kansa,” is an open-source incident response and threat hunting framework for Windows environments. It is built on top of PowerShell and provides a set of modules to collect and analyze data for security investigations and detection of malicious activities.

  • King phisher

    A free and open-source phishing campaign toolkit. King Phisher helps users simulate real-world phishing attacks and includes features such as embedded email images, credential harvesting, and website cloning.

  • Kippo

    Kippo is a medium-interaction SSH honeypot written in Python. Kippo is used to log brute-force attacks and the entire shell interaction performed by an attacker.

  • L0phtCrack

    A free and open-source password auditing and recovery tool. L0phtCrack supports attack techniques, including dictionary and brute-force attacks and rainbow tables.

  • Maltego

    A powerful OSINT and link analysis tool with free and paid versions. Maltego features integrations with dozens of data sources, including Mandiant, Censys, PolySwarm, Splunk, and many more.

  • Medusa

    A free and open-source fast, massively parallel password-cracking tool. Medusa can perform brute-force password testing against multiple hosts or users simultaneously.

  • Memory Forensic System on Cloud

    This repository is a PoC for memory forensic on AWS. This system only supports memory forensics on Windows OS.

  • Microburst

    Assorted scripts for Azure security. MicroBurst includes functions and scripts that support Azure Services discovery, weak configuration auditing, and post exploitation actions such as credential dumping. It is intended to be used during penetration tests where Azure is in use.

  • Mimikatz

    A free and open-source tool for extracting passwords and other credentials from Windows memory. Mimikatz can also perform credential theft attacks such as pass-the-hash and pass-the-ticket.

  • MISP

    MISP (core software) – Open Source Threat Intelligence and Sharing Platform

  • MISP

    MISP Threat Sharing is an open-source threat intelligence platform. The project develops utilities and documentation for more effective threat intelligence, by sharing indicators of compromise.

  • MSTICPy

    Microsoft Threat Intelligence Security Tools. MSTICPy is a set of Python tools intended to be used for security investigations and hunting. Many of the tools originated as code Jupyter notebooks written to solve a problem as part of a security investigation.