gabrielrodri33/blue-team-toolkit
GitHub: gabrielrodri33/blue-team-toolkit
一套用于蓝队防御性网络安全操作的 Python 脚本工具集,提供日志分析、入侵检测、端点监控、威胁狩猎、事件响应与 SIEM 关联等模块化能力。
Stars: 0 | Forks: 0
# blue-team-toolkit 🛡️
一个用于 Blue Team 操作的 Python 脚本和工具集合 —— 包括日志分析、入侵检测、端点监控、威胁狩猎、事件响应和 SIEM 关联。
## 模块
| 模块 | 描述 |
|--------|-------------|
| log-analysis | 解析并检测系统/应用日志中的异常 |
| ids | 实时网络入侵检测 |
| endpoint-monitor | 进程、文件完整性和连接追踪 |
| threat-hunting | 使用公开威胁情报源进行 IoC 扫描 |
| incident-response | 证据收集、时间线和报告生成 |
| siem | 基于规则引擎的多源事件关联 |
## 环境要求
- Python 3.10+
- 依赖项:见 requirements.txt
## 安装说明
```
git clone https://github.com/gabrielrodri33/blue-team-toolkit
cd blue-team-toolkit
pip install -r requirements.txt
```
## 用法
每个模块都有各自的 README 和示例。请从 log-analysis/ 开始。
## 文档
完整文档可在 [Wiki](https://github.com/gabrielrodri33/blue-team-toolkit/wiki) 中查看:
- [设置与安装](https://github.com/gabrielrodri33/blue-team-toolkit/wiki/Setup-&-Installation)
- [架构与数据流](https://github.com/gabrielrodri33/blue-team-toolkit/wiki/Architecture)
- [log-analysis](https://github.com/gabrielrodri33/blue-team-toolkit/wiki/log-analysis)
- [ids](https://github.com/gabrielrodri33/blue-team-toolkit/wiki/ids)
- [endpoint-monitor](https://github.com/gabrielrodri33/blue-team-toolkit/wiki/endpoint-monitor)
- [threat-hunting](https://github.com/gabrielrodri33/blue-team-toolkit/wiki/threat-hunting)
- [incident-response](https://github.com/gabrielrodri33/blue-team-toolkit/wiki/incident-response)
- [siem](https://github.com/gabrielrodri33/blue-team-toolkit/wiki/siem)
- [贡献指南](https://github.com/gabrielrodri33/blue-team-toolkit/wiki/Contributing)
## 路线图
- [ ] log-analysis
- [ ] ids
- [ ] endpoint-monitor
- [ ] threat-hunting
- [ ] incident-response
- [ ] siem
## 作者
Gabriel Siqueira — [LinkedIn](https://linkedin.com/in/gabrielrodri)
标签:HTTP工具, Mr. Robot, Python, 子域名变形, 库, 应急响应, 无后门, 终端监控, 网络安全审计, 逆向工具