Ross ROSS = Recommend OSS · open-source software intelligence for agents

ION28/BLUESPAWN

An Active Defense and EDR software to empower Blue Teams observed · 2026-08-28

github.com/ION28/BLUESPAWN · C++ · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

69/100

  • Activity 74
  • Release rhythm 45
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2654
  • days_rel: 156
  • days_push: 156
  • n_releases_24m: 1

Full methodology

Adoption not part of the score

1334 stars · 177 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

BLUESPAWN is an open-source active defense and endpoint detection and response (EDR) tool for Windows. It helps blue teams detect, identify, and eliminate malicious activity and malware in real time, with detections mapped to MITRE ATT&CK.

Use cases

  • detect malware on windows endpoints
  • threat hunting on windows systems
  • monitor systems for active attacker behavior
  • map endpoint detections to mitre att&ck
  • open-source alternative to commercial EDR
  • hunt persistence mechanisms on compromised hosts

When to choose

  • you are a blue team defending Windows endpoints
  • you want transparent, open-source detection logic mapped to MITRE ATT&CK
  • you need a lightweight tool to hunt and remove malware during incident response

When to avoid

  • you need cross-platform (Linux/macOS) endpoint protection
  • you require enterprise-grade EDR with managed response and support
  • you need protection for non-Windows servers or cloud workloads

Facets

application · maturity active

security monitoring alerting vulnerability-scanning security windows developer-tools windows cpp edr blue-team mitre-attack threat-hunting active-defense endpoint-security malware-detection

1 source

Member repositories

RepositoryRoleHealth v2
ION28/BLUESPAWNmain69

For agents

markdown · JSON · MCP: product_card(name="ION28/BLUESPAWN")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem