
ecs-templates
Corelight or Zeek Elastic Common Schema Templates
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Corelight or Zeek Elastic Common Schema Templates

Mapping Corelight or Zeek data to Elastic Common Schema fields

CVE-2026-52813 (Gogs Path Traversal → Git Hooks RCE) defensive writeup: root-cause & patch analysis, Sigma/SIEM detection rules, IOCs, non-intrusive…

🛡️Awesome lists about all kinds of interesting topics of Wazuh XDR/SIEM

AI runtime inventory: discover shadow AI, trace LLM calls

Next-Gen GUI-based WiFi and Bluetooth Analyzer for Linux

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

A modular, skill-based autonomous Security Operations Center (SOC) agent that monitors OpenSearch/Elasticsearch data, builds RAG-based behavioral…

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

Defensive NGINX CVE-2026-42533 map regex risk audit with config scanner, Splunk/Defender notes, and lab evidence.

Defensive Windows security application providing compensating controls for CVE-2017-0144 (EternalBlue/MS17-010) through SMB monitoring, attack…

Lightweight scanner that detects vulnerable Log4j versions and Log4Shell (CVE-2021-44228) indicators in a filesystem tree.

An open-source, single-script CVE scanner for RMM-managed fleets. Pure PowerShell 7 — joins your RMM software inventory against NVD, CISA KEV, EPSS…

This repository contains a list of new remediation scripts.

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.

Experimental Decoy Broker

Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…