
joy
A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.
anomaly-detectiondigital-forensicsdns-analysis+7
1.4k

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

ETW based POC to identify direct and indirect syscalls

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

Open source entropy based invalid traffic detection and pre-bid filtering.

First iteration of ML based Feedback WAF

A Zeek OSPF packet analyzer based on Spicy.

Reverse Shell Detection with Machine Learning


A Zeek based AsyncRAT malware detector.

A Zeek based Mitre Caldera detector.

CVE-2020-9483 OR CVE-2020-13921
