
Tylium
Primary data pipelines for intrusion detection, security analytics and threat hunting
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Primary data pipelines for intrusion detection, security analytics and threat hunting

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

Mapping Corelight or Zeek data to Elastic Common Schema fields

A repository hosting example goodware evtx logs containing sample software installation and basic user interaction

XDP Based Lightweight and Fast Firewall

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

Lightweight macOS detection agent built on Santa’s Endpoint Security telemetry.

analyze a web-based network traffic 🕶 to detect central command and control servers

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

AI agent set for cloud security purple teaming, runs inside Claude Code, Gemini CLI, and Codex.

tshark + ELK analytics virtual machine

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

Enhanced SSH client with TUI — manage connections, keys, and sessions

Semantic Observability for UNIX Systems - A lightweight C-based system prober with AI-powered analysis

TheLightScope

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

Real-time guardrails for Claude Code tool calls.