ION28/BLUESPAWN
An Active Defense and EDR software to empower Blue Teams observed · 2026-08-28
Health v2 · maintenance only
69/100
- Activity 74
- Release rhythm 45
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2654
- days_rel: 156
- days_push: 156
- n_releases_24m: 1
Adoption not part of the score
1334 stars · 177 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
BLUESPAWN is an open-source active defense and endpoint detection and response (EDR) tool for Windows. It helps blue teams detect, identify, and eliminate malicious activity and malware in real time, with detections mapped to MITRE ATT&CK.
Use cases
- detect malware on windows endpoints
- threat hunting on windows systems
- monitor systems for active attacker behavior
- map endpoint detections to mitre att&ck
- open-source alternative to commercial EDR
- hunt persistence mechanisms on compromised hosts
When to choose
- you are a blue team defending Windows endpoints
- you want transparent, open-source detection logic mapped to MITRE ATT&CK
- you need a lightweight tool to hunt and remove malware during incident response
When to avoid
- you need cross-platform (Linux/macOS) endpoint protection
- you require enterprise-grade EDR with managed response and support
- you need protection for non-Windows servers or cloud workloads
Facets
application · maturity active
security monitoring alerting vulnerability-scanning security windows developer-tools windows cpp edr blue-team mitre-attack threat-hunting active-defense endpoint-security malware-detection
1 source
- readme: https://github.com/ION28/BLUESPAWN · fetched 2026-08-28 · 178b5d14aaee
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| ION28/BLUESPAWN | main | 69 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem