
SysTrace
Linux system-call monitor using ptrace to trace file, process, network, and memory activity, with namespace isolation and machine learning…

Linux system-call monitor using ptrace to trace file, process, network, and memory activity, with namespace isolation and machine learning…

Automatic extraction of relevant features from time series:

Programmable guardrails for LLM chat apps: enforce input/output rails, block jailbreaks and prompt injections, detect hallucination, and mask…

A machine learning toolkit for log-based anomaly detection [ISSRE'16]

A deep learning toolkit for log-based anomaly detection

ETW based POC to identify direct and indirect syscalls

A Zeek based AsyncRAT malware detector.

A Zeek based Mitre Caldera detector.

A Zeek OSPF packet analyzer based on Spicy.

Lightweight Python-based IDS that monitors network traffic in real-time using Scapy, detecting DoS/DDoS attacks via per-IP request rate analysis with…

This repository provides an in-depth analysis of the Log4Shell vulnerability (CVE-2021-44228) and implements a machine learning-based approach to…

CVE-2020-9483 OR CVE-2020-13921

Reverse Shell Detection with Machine Learning

ESPectre - Motion detection system based on Wi-Fi spectre analysis (CSI), with Home Assistant integration.

Graph-based insider threat detection using GCN-BiLSTM and attention models on CMU CERT datasets. Includes data preprocessing, feature extraction, and…

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

Open source entropy based invalid traffic detection and pre-bid filtering.

Web-based Traffic and Cybersecurity Network Traffic Monitoring