
fastnetmon
Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Collection of Google Cloud solution examples and operational utilities for audit log monitoring, DLP de-identification, encryption key management,…

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

Single-host runtime-security dashboard on eBPF — Go agent + SvelteKit. Live process tree, network map, and rule-based alerts for plain Linux hosts.

OSTE WLA automate the process of analyzing web server logs with the Python Web Log Analyzer.

Basic log analysis tool to detect impossible travel via IP address geographic information

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon

A Bro package to identify connections that are bursting (lots of data and transferring quickly).

This repository provides an in-depth analysis of the Log4Shell vulnerability (CVE-2021-44228) and implements a machine learning-based approach to…