
zeek
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Runtime application self-protection engine that hooks into application servers to monitor and block malicious database queries, file operations, and…

Open-source security framework for real-time event tracking, threat detection, and risk scoring. Monitors user behavior, detects fraud, bot attacks,…

Monitor your local neighbourhood's bluetooth activity

ETW based POC to identify direct and indirect syscalls

With Wireshark or TCPdump, you can determine whether there is harmful activity on your network traffic that you have recorded on the network you…

OS-level monitor for AI agents: observes processes, file access, and network activity on the local machine and attributes each event to an agent…

The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from…

Monitor large transactions on Polymarket and Kalshi prediction markets with anomaly detection

Linux system-call monitor using ptrace to trace file, process, network, and memory activity, with namespace isolation and machine learning…

Linux kernel-space HID injection attack detector using eBPF. Monitors USB and Bluetooth HID devices for anomalous keystroke timing and automatically…

CVE-2020-9483 OR CVE-2020-13921

Lightweight Python-based IDS that monitors network traffic in real-time using Scapy, detecting DoS/DDoS attacks via per-IP request rate analysis with…
