
KOOBE-Guard
Linux kernel module using Kprobes to detect and neutralize CVE-2024-1086 heap double-free exploits via temporal gap tracking and active register…

Linux kernel module using Kprobes to detect and neutralize CVE-2024-1086 heap double-free exploits via temporal gap tracking and active register…

Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

Default Detections for EDR

ETW based POC to identify direct and indirect syscalls

Small tool to play with IOCs caused by Imageload events

Enumerate various traits from Windows processes as an aid to threat hunting

Basic log analysis tool to detect impossible travel via IP address geographic information

A canary designed to minimize the impact from certain Ransomware actors

The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from…

A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection

A Bro package to identify connections that are bursting (lots of data and transferring quickly).


DNS Dashboard for hunting and identifying beaconing

Detect HTTP stalling attacks like slowloris with Bro