Home
Softono
n

nsacyber

Professional software vendor delivering innovative solutions on the Softono platform. Specialized in both open-source and proprietary software development.

Total Products
2

Software by nsacyber

HIRS
Open Source

HIRS

Host Integrity at Runtime and Start-up (HIRS) is a Proof of Concept prototype developed by the National Security Agency Cybersecurity Directorate to demonstrate Trusted Platform Module (TPM) 2.0 provisioning and supply chain validation. The software features a web-based Attestation Certificate Authority (ACA) that processes identity requests and issues Attestation Certificates or Local Device ID certificates to validated devices. It includes a provisioner application for installation on client devices. Key capabilities include performing TCG-based supply chain validation known as an Acceptance Test, which optionally validates Endorsement and Platform Certificates to verify hardware provenance against manufacturer records. The system also conducts firmware integrity validation by processing Reference Integrity Manifests, verifying TPM Quotes against event logs, and ensuring boot file hashes match OEM specifications. HIRS is designed strictly for testing and development purposes to spur adoption of trusted comp

Security Compliance & Governance
210 Github Stars
Event-Forwarding-Guidance
Open Source

Event-Forwarding-Guidance

Event-Forwarding-Guidance is a configuration guidance repository for implementing the collection of security-relevant Windows Event Log events using Windows Event Forwarding. It serves as a companion to an NSA paper on spotting adversaries through Windows Event Log monitoring, providing a more current list of recommended events to monitor. The repository is useful with both WEF and third-party SIEM solutions as a starting point for log collection strategy. It includes recommended Windows events to collect for security monitoring, PowerShell scripts to create custom Event Log views and WEF subscriptions, and sample WEF subscriptions in XML format. Microsoft documentation on security audit policies, intrusion detection, and event logging are referenced for administrators implementing the guidance.

Log Management
886 Github Stars