
tirreno
Open-source security framework for real-time event tracking, threat detection, and risk scoring. Monitors user behavior, detects fraud, bot attacks,…

Open-source security framework for real-time event tracking, threat detection, and risk scoring. Monitors user behavior, detects fraud, bot attacks,…

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Enumerate various traits from Windows processes as an aid to threat hunting

With Wireshark or TCPdump, you can determine whether there is harmful activity on your network traffic that you have recorded on the network you…

A canary designed to minimize the impact from certain Ransomware actors

OSINT - Data Visualization - Blockchain - Awareness - Scam

The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from…


amavis is a high-performance email content filter framework written in Perl.

Research related to the Power Tracks discovered in market microstructure.

Monitor large transactions on Polymarket and Kalshi prediction markets with anomaly detection

Sigma detection rules for AI agent security monitoring


Fingerprint SSH clients and servers.

This repository demonstrates a machine learning pipeline for detecting MITRE ATT&CK techniques from logs and enriching the output using a local LLM.