Labs to practice
SANS Blue Team - SANS Network Security Operations Curriculum
BlueTeam Tools - This github repository contains a collection of 65+ tools and resources that can be useful for blue teaming activities.
Threat Intel
MISP - MISP Threat Sharing is an open source threat intelligence platform
Maltego - Maltego is link analysis software used for open-source intelligence, forensics and other investigations
Reverse Engineering
IDA - The Interactive Disassembler is a disassembler for computer software which generates assembly language source code from machine-executable code.
Ghidra - Ghidra is a free and open source reverse engineering tool developed by the National Security Agency of the United States.
Digital Forensics
SANS SIFT - The SIFT Workstation is a collection of free and open-source incident response and forensic tools designed to perform detailed digital forensic examinations in a variety of settings.
Autopsy - Autopsy is the premier end-to-end open source digital forensics platform.
SIEM
Splunk - Splunk is software for searching, monitoring, and analyzing machine-generated data via a web-style interface.
ELK - The ELK stack is an acronym used to describe a stack that comprises three popular projects: Elasticsearch, Logstash, and Kibana.
Incident Response
TheHive - TheHive is a scalable Security Incident Response Platform, tightly integrated with MISP (Malware Information Sharing Platform)
GRR Rapid Response - GRR Rapid Response is an incident response framework focused on remote live forensics.
Endpoint
Velociraptor EDR - Velociraptor is an advanced digital forensic and incident response tool that enhances your visibility into your endpoints.
Wazuh - Wazuh is a free and open source security platform that unifies XDR and SIEM protection for endpoints and cloud workloads.
Network
nmap - Network Mapper
Network Miner - NetworkMiner is an open source network forensics tool
Wireshark - The world’s most popular network protocol analyzer
Zeek - An Open Source Network Security Monitoring Tool
Snort - Snort is the foremost Open Source Intrusion Prevention System (IPS) in the world.
Suricata - Suricata is a high performance, open source network analysis and threat detection software
Arkime - Network Analysis & Packet Capture
Malware Traffic Analysis - Download malicious PCAP (packet capture) files to learn how to analyze malicious network behavior Contains Malware
Vulnerability Management
OpenVAS - OpenVAS is a full-featured vulnerability scanner.
Tenable Nessus Essentials - Tenable Nessus Essentials allows you to scan your environment (up to 16 IP addresses per scanner)