
DeTTECT
Detect Tactics, Techniques & Combat Threats
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Detect Tactics, Techniques & Combat Threats

A repo to hold KQL queries as part of my 100 days of KQL effort.

Spip network sensor written in Go

Universal mobile devtool for Agents & Humans - control iOS Simulators, Android Emulators, and real devices from a single dashboard and CLI

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

DECeption with Evaluative Integrated Validation Engine (DECEIVE): Let an LLM do all the hard honeypot work!

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…

Rapidly Search and Hunt through Windows Forensic Artefacts

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

Multi-threaded Windows event log forensics timeline generator and threat hunting tool with full Sigma rule support, producing CSV/JSON timelines for…

Sanitised Windows security lab demonstrating Active Directory administration, host and network detection, and layered mitigation of CVE-2021-34527.

Detects shadow-administrator accounts in WordPress via configurable indicators and heuristics, then removes selected accounts through guarded, logged…

CY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271

Operational security controls with forensic guarantees

Investigate malicious Windows logon by visualizing and analyzing Windows event log

Audits Windows event log settings against best-practice guidelines and Sigma-rule detectability, with automated configuration for DFIR readiness.