
DetectWindowsCopyOnWriteForAPI
Enumerate various traits from Windows processes as an aid to threat hunting

Enumerate various traits from Windows processes as an aid to threat hunting

[NeurIPS 2025] An official source code for paper "GuardReasoner-VL: Safeguarding VLMs via Reinforced Reasoning".

A tool for malicious behavior detection in IoT devices

OSTE WLA automate the process of analyzing web server logs with the Python Web Log Analyzer.

Zeek package for tracking long connections to report them before they have completed.

Sigma detection rules for AI agent security monitoring

Small tool to play with IOCs caused by Imageload events

DGA-generated domain detection using deep learning models

My experiments in weaponizing ONOS applications (https://github.com/opennetworkinglab/onos)

A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection

Detect HTTP stalling attacks like slowloris with Bro

Framework for implementing Network Intrusion Detection Systems (NIDS) aimed at identifying anomalies in network flows using Federated Learning models.

Basic log analysis tool to detect impossible travel via IP address geographic information

Multivariate statistical network monitoring sensor that detects anomalies using PCA-based techniques, aggregating lightweight statistics from…

A Zeek OSPF packet analyzer based on Spicy.


Detects LLM context-leakage attacks by training lightweight behavior probes on log-probabilities, with vLLM offline/server detection pipelines.

Production AI defense with 7-layer protection: mathematical constraints, object-capability access, distributed O2 consensus, SVETILO ethics. First…