Open source & live tools

Projects

Open-source tooling, methodology, and research released through Red Spectrum.

The tools and references below are released publicly to support the broader security community. Several are used in Red Spectrum engagements; others exist because the gap they fill wasn’t being filled elsewhere.

Live Tools

WFPS Incidents

● Live

Real-time Winnipeg Fire Paramedic Service incident tracker. Aggregates and visualizes active incident data for public situational awareness.

livedatavisualization

TSCM-TAFL

● Live

Hosted interface for the TSCM Threat Actor Frequency Library — reference data supporting RF-side Technical Surveillance Countermeasures operations.

livetscmrfsignals

GitHub

PowerHuntShares-dotnet

C#

.NET port of PowerHuntShares for discovering, analyzing, and reporting excessive privileges on SMB shares in Active Directory environments.

active-directorysmbrecon

SMBAudit

PowerShell

SMB share auditing tooling focused on identifying misconfigurations, weak ACLs, and sensitive data exposure across enterprise file shares.

smbauditblue-team-input

Jir-Thief

Python

Jira credential and data extraction tooling for red team engagements where Atlassian ecosystems are in scope.

red-teamatlassianpost-ex

OWASP-API-Checklist

Markdown

Practical checklist mapped to the OWASP API Security Top 10 for use during web/API penetration tests and design reviews.

apiowaspmethodology

TSCMTAFL

Python

Technical Surveillance Countermeasures — Threat Actor Frequency Library. Reference data and tooling supporting RF-side TSCM operations.

tscmrfsignals

CL_MAL_LSS

C

Custom loader/staging research for offensive tradecraft and EDR evasion testing in controlled red team engagements.

red-teammalware-devedr-evasion