
ddos-traffic-monitor
A real-time traffic monitoring tool that detects and displays network traffic volume per IP address to identify potential DDoS attacks.

A real-time traffic monitoring tool that detects and displays network traffic volume per IP address to identify potential DDoS attacks.

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

Network monitoring tool that maps process-to-network connections, identifies cloud providers, and detects beaconing activity

NOVA - Claude Code Protection System against prompt injection attacks

Small tool to play with IOCs caused by Imageload events

Deep Learning models for network traffic classification

Basic log analysis tool to detect impossible travel via IP address geographic information

Real-time monitoring and slowlog analysis for Valkey and Redis databases with anomaly detection, ACL auditing, and Prometheus metrics export.

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

DNS Dashboard for hunting and identifying beaconing

AI-driven endpoint governance platform that monitors software usage, applies deterministic policy-based risk classification, and generates structured…

Autoencoder-based anomaly detection for identifying phishing domains using CERT Polska warning list data, with Jupyter notebooks for research and…

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

A machine learning toolkit for log parsing [ICSE'19, DSN'16]

Linux system-call monitor using ptrace to trace file, process, network, and memory activity, with namespace isolation and machine learning…

Linux kernel-space HID injection attack detector using eBPF. Monitors USB and Bluetooth HID devices for anomalous keystroke timing and automatically…

Collection of KQL queries

WiFi, Bluetooth and Ethernet Intrusion Detection.