gabrielrodri33/blue-team-toolkit

GitHub: gabrielrodri33/blue-team-toolkit

一套用于蓝队防御性网络安全操作的 Python 脚本工具集,提供日志分析、入侵检测、端点监控、威胁狩猎、事件响应与 SIEM 关联等模块化能力。

Stars: 0 | Forks: 0

# blue-team-toolkit 🛡️ 一个用于 Blue Team 操作的 Python 脚本和工具集合 —— 包括日志分析、入侵检测、端点监控、威胁狩猎、事件响应和 SIEM 关联。 ## 模块 | 模块 | 描述 | |--------|-------------| | log-analysis | 解析并检测系统/应用日志中的异常 | | ids | 实时网络入侵检测 | | endpoint-monitor | 进程、文件完整性和连接追踪 | | threat-hunting | 使用公开威胁情报源进行 IoC 扫描 | | incident-response | 证据收集、时间线和报告生成 | | siem | 基于规则引擎的多源事件关联 | ## 环境要求 - Python 3.10+ - 依赖项:见 requirements.txt ## 安装说明 ``` git clone https://github.com/gabrielrodri33/blue-team-toolkit cd blue-team-toolkit pip install -r requirements.txt ``` ## 用法 每个模块都有各自的 README 和示例。请从 log-analysis/ 开始。 ## 文档 完整文档可在 [Wiki](https://github.com/gabrielrodri33/blue-team-toolkit/wiki) 中查看: - [设置与安装](https://github.com/gabrielrodri33/blue-team-toolkit/wiki/Setup-&-Installation) - [架构与数据流](https://github.com/gabrielrodri33/blue-team-toolkit/wiki/Architecture) - [log-analysis](https://github.com/gabrielrodri33/blue-team-toolkit/wiki/log-analysis) - [ids](https://github.com/gabrielrodri33/blue-team-toolkit/wiki/ids) - [endpoint-monitor](https://github.com/gabrielrodri33/blue-team-toolkit/wiki/endpoint-monitor) - [threat-hunting](https://github.com/gabrielrodri33/blue-team-toolkit/wiki/threat-hunting) - [incident-response](https://github.com/gabrielrodri33/blue-team-toolkit/wiki/incident-response) - [siem](https://github.com/gabrielrodri33/blue-team-toolkit/wiki/siem) - [贡献指南](https://github.com/gabrielrodri33/blue-team-toolkit/wiki/Contributing) ## 路线图 - [ ] log-analysis - [ ] ids - [ ] endpoint-monitor - [ ] threat-hunting - [ ] incident-response - [ ] siem ## 作者 Gabriel Siqueira — [LinkedIn](https://linkedin.com/in/gabrielrodri)
标签:HTTP工具, Mr. Robot, Python, 子域名变形, 库, 应急响应, 无后门, 终端监控, 网络安全审计, 逆向工具