Blue Team Arsenal Tool List
The following is a complete list of Blue Team tools (Defensive Security) as posted in my Cyber Security Arsenal Catalog organized in a simple and logical way to make it easier to navigate.
Every Index node will take you the tool section. Every tool will also be linked to another Complete Command Reference post for the given tool, where you can learn how to use it fully.
I hope you enjoy.
Index
SIEM
EDR / XDR
NSM & IDS/IPS
DFIR
Threat Intelligence
SOAR
Deception
Cloud native security (defensive)
Firewall & network control
Malware analysis
Vulnerability & asset management
Identity & access defense
Blue Team Complete Tool List
SIEM
- Apache Kafka (security pipelines)
- ArcSight
- Chronicle (Google SecOps)
- Cribl
- Elastic SIEM / ELK Stack
- Fluent Bit / Fluentd
- Grafana Loki
- Graylog
- HELK
- IBM QRadar
- LogRhythm
- Microsoft Sentinel
- OpenSearch Security Analytics
- OSSIM
- rsyslog
- Security Onion
- Splunk
- Sumo Logic
- syslog-ng
- Vector
- Wazuh
EDR / XDR
- Auditd
- Carbon Black
- Cortex XDR
- CrowdStrike Falcon
- CrowdStrike Falcon Insight
- Cybereason
- Elastic Agent / Elastic Endpoint
- Falco
- GRR Rapid Response
- LimaCharlie
- Microsoft Defender for Endpoint
- OSQuery
- osquery + Fleet
- SentinelOne
- Sophos Intercept X
- Sysmon
- Tetragon
- Tracee
- Trend Micro Apex One
- Velociraptor
- Wazuh Agent
- Wazuh + Elastic stacks
NSM & IDS/IPS
- Arkime
- Brim / Zui
- Cisco Secure Network Analytics
- Corelight
- Darktrace
- ExtraHop
- Moloch (legacy name)
- NetworkMiner
- ntopng
- Packetbeat
- pfSense / OPNsense IDS
- Security Onion
- Snort
- Stenographer
- Suricata
- Vectra
- Zeek
- Zeek packages (zkg)
DFIR
- AFF4 / libewf tools
- Arsenal Image Mounter
- Autopsy
- Belkasoft
- Bulk Extractor
- bulk_extractor
- Capa
- Chainsaw
- CyberChef
- Dissect
- EnCase
- Eric Zimmerman Tools
- EVTX tools
- Foremost
- FTK Imager
- Google Rapid Response (GRR)
- Hayabusa
- HxD
- KAPE
- Magnet AXIOM
- Mandiant Redline
- NirSoft suite
- OSForensics
- PhotoRec
- Plaso / log2timeline
- Redline
- Registry Explorer
- RegRipper
- Rekall
- Scalpel
- Sysinternals Suite
- TestDisk
- The Sleuth Kit
- Timeline Explorer
- Timesketch
- Volatility / Volatility 3
- X-Ways Forensics
- YARA / YARA-X
- Zircolite
Threat Intelligence
- AbuseIPDB
- AlienVault OTX
- Anomali
- Any.Run
- ATT&CK Navigator
- BinaryEdge
- Censys
- Cortex Analyzers
- DomainTools
- Feodo Tracker
- GreyNoise
- Hybrid Analysis
- IntelMQ
- Malpedia
- MalwareBazaar
- MISP
- MITRE ATT&CK
- OpenCTI
- PassiveTotal / RiskIQ
- Pulsedive
- Recorded Future
- Shodan
- SpiderFoot (intel mode)
- STIX/TAXII tooling
- TheHive
- ThreatConnect
- ThreatFox
- ThreatFox API
- URLScan.io
- URLhaus
- VirusTotal
- vx-underground (intel source)
- Yeti
SOAR
- Ansible (IR automation)
- Cortex
- Cortex XSOAR
- FastIR
- IRIS
- Microsoft Sentinel playbooks
- n8n
- Shuffle
- Shuffle + Wazuh pipelines
- Siemplify
- Splunk SOAR
- StackStorm
- Swimlane
- TheHive
- Tines
- Torq
- XSOAR content packs
Deception
- Attivo / Acalvio
- Canarytokens
- Conpot
- Dionaea
- Elastic Honey
- Glutton
- HoneyDB
- Honeytrap
- Kippo / Cowrie
- Modern Honey Network
- OpenCanary
- SNARE / TANNER
- Thinkst Canary
- TrapX
- Wordpot
Cloud native security (defensive)
- Aqua Security
- AWS Config
- AWS Detective
- AWS GuardDuty
- AWS Macie
- AWS Security Hub
- Azure Policy
- Checkov
- CloudTrail Insights
- Falco (K8s runtime)
- GCP Security Command Center
- KICS
- Kubescape
- Kyverno
- Lacework
- Microsoft Defender for Cloud
- OPA / Gatekeeper
- Orca Security
- Prisma Cloud
- Sysdig Secure
- Terrascan
- Tetragon
- tfsec
- Trivy IaC
- Wiz
Firewall & network control
- AWS WAF / Azure WAF / Cloudflare WAF
- Check Point
- Cisco ASA / Firepower
- CrowdSec
- Fail2ban
- firewalld
- Fortinet FortiGate
- iptables / nftables
- Juniper SRX
- ModSecurity
- NAXSI
- OPNsense
- Palo Alto NGFW
- pfSense
- shorewall
- Squid (ACL/proxy control)
- ufw
- Windows Firewall / WFP tooling
- Zero Trust (Zscaler, Cloudflare ZT, Tailscale ACLs)
Malware analysis
- Any.Run
- CAPEv2
- Capa
- Cuckoo Sandbox
- de4dot
- Detect It Easy
- eml_parser
- FLOSS
- Hybrid Analysis
- Intezer
- Intezer Analyze
- Joe Sandbox
- Malcat
- OLETools / olevba
- pdf-parser / peepdf
- PEStudio
- Polyswarm
- Qiling
- Speakeasy
- UPX
- Viper
- VirusTotal
- XLMMacroDeobfuscator
- YARA
- (RE platforms: see Red Team → Reverse Engineering)
Vulnerability & asset management
- Armis
- Axonius
- CMDB integrations
- Greenbone / OpenVAS
- Lansweeper
- Microsoft Defender Vulnerability Management
- Nmap inventory pipelines
- Nuclei (scheduled asset scans)
- Qualys VMDR
- Rapid7 InsightVM
- RunZero
- ServiceNow VR
- Tenable.io / Nessus
Identity & access defense
- AADInternals (audit)
- AD ACL Scanner
- ADAudit Plus-style tooling
- Azure AD Connect health monitoring
- BloodHound (defensive)
- CrowdStrike / Defender identity
- Entra ID monitoring
- Okta / Duo / conditional access
- PingCastle
- Privileged Identity Management (PIM)
- Purple Knight
- RoadTools (audit mode)