◄ BACKDOCBLUE TEAM ARSENAL TOOL LIST

Blue Team Arsenal Tool List

The following is a complete list of Blue Team tools (Defensive Security) as posted in my Cyber Security Arsenal Catalog organized in a simple and logical way to make it easier to navigate.

Every Index node will take you the tool section. Every tool will also be linked to another Complete Command Reference post for the given tool, where you can learn how to use it fully.

I hope you enjoy.

Index

SIEM

EDR / XDR

NSM & IDS/IPS

DFIR

Threat Intelligence

SOAR

Deception

Cloud native security (defensive)

Firewall & network control

Malware analysis

Vulnerability & asset management

Identity & access defense

Blue Team Complete Tool List

SIEM

  • Apache Kafka (security pipelines)
  • ArcSight
  • Chronicle (Google SecOps)
  • Cribl
  • Elastic SIEM / ELK Stack
  • Fluent Bit / Fluentd
  • Grafana Loki
  • Graylog
  • HELK
  • IBM QRadar
  • LogRhythm
  • Microsoft Sentinel
  • OpenSearch Security Analytics
  • OSSIM
  • rsyslog
  • Security Onion
  • Splunk
  • Sumo Logic
  • syslog-ng
  • Vector
  • Wazuh

EDR / XDR

  • Auditd
  • Carbon Black
  • Cortex XDR
  • CrowdStrike Falcon
  • CrowdStrike Falcon Insight
  • Cybereason
  • Elastic Agent / Elastic Endpoint
  • Falco
  • GRR Rapid Response
  • LimaCharlie
  • Microsoft Defender for Endpoint
  • OSQuery
  • osquery + Fleet
  • SentinelOne
  • Sophos Intercept X
  • Sysmon
  • Tetragon
  • Tracee
  • Trend Micro Apex One
  • Velociraptor
  • Wazuh Agent
  • Wazuh + Elastic stacks

NSM & IDS/IPS

  • Arkime
  • Brim / Zui
  • Cisco Secure Network Analytics
  • Corelight
  • Darktrace
  • ExtraHop
  • Moloch (legacy name)
  • NetworkMiner
  • ntopng
  • Packetbeat
  • pfSense / OPNsense IDS
  • Security Onion
  • Snort
  • Stenographer
  • Suricata
  • Vectra
  • Zeek
  • Zeek packages (zkg)

DFIR

  • AFF4 / libewf tools
  • Arsenal Image Mounter
  • Autopsy
  • Belkasoft
  • Bulk Extractor
  • bulk_extractor
  • Capa
  • Chainsaw
  • CyberChef
  • Dissect
  • EnCase
  • Eric Zimmerman Tools
  • EVTX tools
  • Foremost
  • FTK Imager
  • Google Rapid Response (GRR)
  • Hayabusa
  • HxD
  • KAPE
  • Magnet AXIOM
  • Mandiant Redline
  • NirSoft suite
  • OSForensics
  • PhotoRec
  • Plaso / log2timeline
  • Redline
  • Registry Explorer
  • RegRipper
  • Rekall
  • Scalpel
  • Sysinternals Suite
  • TestDisk
  • The Sleuth Kit
  • Timeline Explorer
  • Timesketch
  • Volatility / Volatility 3
  • X-Ways Forensics
  • YARA / YARA-X
  • Zircolite

Threat Intelligence

  • AbuseIPDB
  • AlienVault OTX
  • Anomali
  • Any.Run
  • ATT&CK Navigator
  • BinaryEdge
  • Censys
  • Cortex Analyzers
  • DomainTools
  • Feodo Tracker
  • GreyNoise
  • Hybrid Analysis
  • IntelMQ
  • Malpedia
  • MalwareBazaar
  • MISP
  • MITRE ATT&CK
  • OpenCTI
  • PassiveTotal / RiskIQ
  • Pulsedive
  • Recorded Future
  • Shodan
  • SpiderFoot (intel mode)
  • STIX/TAXII tooling
  • TheHive
  • ThreatConnect
  • ThreatFox
  • ThreatFox API
  • URLScan.io
  • URLhaus
  • VirusTotal
  • vx-underground (intel source)
  • Yeti

SOAR

  • Ansible (IR automation)
  • Cortex
  • Cortex XSOAR
  • FastIR
  • IRIS
  • Microsoft Sentinel playbooks
  • n8n
  • Shuffle
  • Shuffle + Wazuh pipelines
  • Siemplify
  • Splunk SOAR
  • StackStorm
  • Swimlane
  • TheHive
  • Tines
  • Torq
  • XSOAR content packs

Deception

  • Attivo / Acalvio
  • Canarytokens
  • Conpot
  • Dionaea
  • Elastic Honey
  • Glutton
  • HoneyDB
  • Honeytrap
  • Kippo / Cowrie
  • Modern Honey Network
  • OpenCanary
  • SNARE / TANNER
  • Thinkst Canary
  • TrapX
  • Wordpot

Cloud native security (defensive)

  • Aqua Security
  • AWS Config
  • AWS Detective
  • AWS GuardDuty
  • AWS Macie
  • AWS Security Hub
  • Azure Policy
  • Checkov
  • CloudTrail Insights
  • Falco (K8s runtime)
  • GCP Security Command Center
  • KICS
  • Kubescape
  • Kyverno
  • Lacework
  • Microsoft Defender for Cloud
  • OPA / Gatekeeper
  • Orca Security
  • Prisma Cloud
  • Sysdig Secure
  • Terrascan
  • Tetragon
  • tfsec
  • Trivy IaC
  • Wiz

Firewall & network control

  • AWS WAF / Azure WAF / Cloudflare WAF
  • Check Point
  • Cisco ASA / Firepower
  • CrowdSec
  • Fail2ban
  • firewalld
  • Fortinet FortiGate
  • iptables / nftables
  • Juniper SRX
  • ModSecurity
  • NAXSI
  • OPNsense
  • Palo Alto NGFW
  • pfSense
  • shorewall
  • Squid (ACL/proxy control)
  • ufw
  • Windows Firewall / WFP tooling
  • Zero Trust (Zscaler, Cloudflare ZT, Tailscale ACLs)

Malware analysis

  • Any.Run
  • CAPEv2
  • Capa
  • Cuckoo Sandbox
  • de4dot
  • Detect It Easy
  • eml_parser
  • FLOSS
  • Hybrid Analysis
  • Intezer
  • Intezer Analyze
  • Joe Sandbox
  • Malcat
  • OLETools / olevba
  • pdf-parser / peepdf
  • PEStudio
  • Polyswarm
  • Qiling
  • Speakeasy
  • UPX
  • Viper
  • VirusTotal
  • XLMMacroDeobfuscator
  • YARA
  • (RE platforms: see Red Team → Reverse Engineering)

Vulnerability & asset management

  • Armis
  • Axonius
  • CMDB integrations
  • Greenbone / OpenVAS
  • Lansweeper
  • Microsoft Defender Vulnerability Management
  • Nmap inventory pipelines
  • Nuclei (scheduled asset scans)
  • Qualys VMDR
  • Rapid7 InsightVM
  • RunZero
  • ServiceNow VR
  • Tenable.io / Nessus

Identity & access defense

  • AADInternals (audit)
  • AD ACL Scanner
  • ADAudit Plus-style tooling
  • Azure AD Connect health monitoring
  • BloodHound (defensive)
  • CrowdStrike / Defender identity
  • Entra ID monitoring
  • Okta / Duo / conditional access
  • PingCastle
  • Privileged Identity Management (PIM)
  • Purple Knight
  • RoadTools (audit mode)