#1Tools for blue team, defensive security, and threat protection.
Kitploit recommended

Citrix ADC (NetScaler) Honeypot. Supports detection for CVE-2019-19781 and login attempts

CLI scanner that detects likely vulnerable React/Next.js dependencies for CVE-2025-55182 and provides mitigation targets. Supports JSON output and…

My manifesto, and stories, images, and phun stuff

AIEngine is a next generation interactive/programmable Python/Ruby/Java/Lua and Go NIDS (Network intrusion detection system).

Proof-of-Concept (POC) of a simple firewall in Python designed to mitigate the Spring4Shell (CVE-2022-22965) RCE attack by inspecting and blocking…

Linux kernel security driver using LSM to harden the system, monitor and restore syscall table integrity, and protect CPU control registers against…

Rust-based tool to detect and mitigate CVE-2024-39930 ptrace exploitation, providing binary-level analysis and defensive countermeasures for Linux…

Python toolkit to audit Apache HTTP Server against CVE-2026-23918 (HTTP/2 double-free RCE) and 4 related CVEs. Passive scanner with ALPN verification…

Security hotfix for CVE-2017-8802

Proof-of-concept exploit for CVE-2017-8570 (Composite Moniker) using Packager.dll file-dropping technique to execute arbitrary SCT payloads via…

这是一个用于防御巡检的 CVE-2026-41089 检测脚本。该漏洞是 Microsoft 在 2026 年 5 月安全更新中披露的 Windows Netlogon 远程代码执行漏洞。

This repository documents how deployment of Microsoft Defender for Endpoint on a Windows 11 device, including onboarding via local script, enabling…

PowerShell script to mitigate CVE-2022-41040 on affected Exchange servers by applying recommended configuration changes.

Fast, configurable HTML sanitization library for preventing XSS and malicious code injection from untrusted user input. Provides a policy-driven API…

This PowerShell script detects indicators of compromise for CVE-2025-53770 — a critical RCE vulnerability in Microsoft SharePoint. Created by…

Menu bar app that monitors SSID changes to automatically reboot a Mac upon device snatching, providing a physical security countermeasure against…

Python-based simulated firewall to detect and block Spring4Shell (CVE-2022-22965) exploit attempts. This project filters HTTP requests by identifying…

A lightweight, real-time Security Information and Event Management (SIEM) dashboard built using Streamlit. It collects system logs, detects USB and…