
rita
Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Suricata rules for network anomaly detection

DNS Proxy that is simple and fast with not so simple features. Focused on routed DNS forwarding, filtering and parental control.

Kernel-runtime defense framework for AF_ALG vulnerabilities, featuring eBPF socket tracing, Ansible hardening, and a crypto auditor for drift…

A Zeek based AsyncRAT malware detector.

Leitwacht control plane — runtime security for GitLab Runner CI/CD: policy authoring, multi-tenancy, audit, GitLab integration

Full-stack security OS for AI agents with five-layer defense-in-depth architecture covering foundation scan, input sanitization, cognition…

Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis,…

Runtime application self-protection engine that hooks into application servers to monitor and block malicious database queries, file operations, and…

A Zeek based Mitre Caldera detector.

Detection for SUNBURST C2 Stage-1 using Shannon Entropy

Detects phi-structured C2 beacons that evade RITA and standard regularity-based detectors

Zeek detector for QuasarRat