
content-packs
Content packs for Eventum
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Content packs for Eventum

Trace every shell environment variable to its exact file and line origin. Audit shell configs for dead entries, duplicates, and orphaned files across…

MDE/MDI Defender setup for Ludus


Reproducible SOC lab for CVE-2024-4577 detection and response

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

End-to-end SOC incident analysis and threat hunting playbook targeting Microsoft SharePoint privilege escalation (CVE-2023-29375) using SIEM logs,…

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

Strelka Web UI for File Submission and Analysis

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

Some of my KQL hunting queries

Converts Sigma detection rules into OpenSearch Lucene and PPL queries, including alerting Monitor Rules and correlation support for SIEM detection…

🐍 High-performance, multi-threaded YARA & IOC scanner

Single-host runtime-security dashboard on eBPF — Go agent + SvelteKit. Live process tree, network map, and rule-based alerts for plain Linux hosts.

Mapping Corelight or Zeek data to Elastic Common Schema logs