# ION28/BLUESPAWN

An Active Defense and EDR software to empower Blue Teams

Repository: https://github.com/ION28/BLUESPAWN
Canonical: https://ross.abutalabs.com/products/bluespawn
Language: C++
License: GPL-3.0
License Family: copyleft
Topics: active-defense, windows, security, security-tools, blue-team, mitre-attack, anti-virus, edr, threat-hunting
Last push: 2026-03-31T02:20:14+00:00

## Health v2 (maintenance only)
Score: 69/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 74, release rhythm 45, longevity 100
- inputs: {"age_days": 2654, "days_push": 156, "days_rel": 156, "gap_med": null, "n_releases_24m": 1}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1334, forks 177 (observed 2026-08-28T04:04:25.163277+00:00)

## What it is
BLUESPAWN is an open-source active defense and endpoint detection and response (EDR) tool for Windows. It helps blue teams detect, identify, and eliminate malicious activity and malware in real time, with detections mapped to MITRE ATT&CK.

## Use cases
- detect malware on windows endpoints
- threat hunting on windows systems
- monitor systems for active attacker behavior
- map endpoint detections to mitre att&ck
- open-source alternative to commercial EDR
- hunt persistence mechanisms on compromised hosts

## When to choose
- you are a blue team defending Windows endpoints
- you want transparent, open-source detection logic mapped to MITRE ATT&CK
- you need a lightweight tool to hunt and remove malware during incident response

## When to avoid
- you need cross-platform (Linux/macOS) endpoint protection
- you require enterprise-grade EDR with managed response and support
- you need protection for non-Windows servers or cloud workloads

## Facets
- artifact type: application
- maturity: active
- function: security, monitoring, alerting, vulnerability-scanning
- domain: security, windows, developer-tools
- platform: windows, cpp
- tags: edr, blue-team, mitre-attack, threat-hunting, active-defense, endpoint-security, malware-detection

## Member repositories
- ION28/BLUESPAWN (main) score 69

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:25.163277+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:44:27.645140+00:00, confidence not recorded.
  - readme: https://github.com/ION28/BLUESPAWN (fetched 2026-08-28T04:04:25.163277+00:00, sha 178b5d14aaee)
- Data as of 2026-08-30T08:39:29.467469+00:00.
