
SysTrace
Linux system-call monitor using ptrace to trace file, process, network, and memory activity, with namespace isolation and machine learning…

Linux system-call monitor using ptrace to trace file, process, network, and memory activity, with namespace isolation and machine learning…

SigCorr is the first open-source tool to detect cross-protocol attack chains spanning SS7/MAP, Diameter S6a, and GTPv2-C through unified subscriber…

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…


A real-time traffic monitoring tool that detects and displays network traffic volume per IP address to identify potential DDoS attacks.

Network monitoring tool that maps process-to-network connections, identifies cloud providers, and detects beaconing activity

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

Small tool to play with IOCs caused by Imageload events

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

A network packet forensics tool for SSH

Basic log analysis tool to detect impossible travel via IP address geographic information

Ability to detect suspicious activity such as (WEP/WPA/WPS) attack by sniffing the air for wireless packets.