Megatron is a tool implemented by CERT-SE for abuse- and incident handling, capable of collecting and analyzing log files with bad machines from sources like Shadowserver. It offers features such as flexible parsing, organization matching, database storage, filtering, data decoration, and various types of lookups.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
An enterprise cybersecurity platform that unifies endpoint, cloud, and identity security through an integrated data lake architecture with AI-powered analysis capabilities.
A case management platform for Security Operations Centers that enables collaborative incident response, workflow automation, and compliance reporting throughout the cybersecurity incident response lifecycle.
A defense-in-depth security automation and monitoring framework utilizing threat intelligence, machine learning, and serverless technologies.
StackStorm is an open-source automation platform that connects and automates DevOps workflows and integrates with existing infrastructure.
A multi-platform open source tool for triaging suspect systems and hunting for Indicators of Compromise (IOCs) across thousands of endpoints.
A framework for improving detection strategies and alert efficacy.
Detailed analysis of the event-stream incident and actions taken by npm Security.
A framework for accumulating, describing, and classifying actionable Incident Response techniques
PowerGRR is a PowerShell module for the GRR API, allowing automation and scripting for incident response and remote live forensics.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.