
columbo
ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

PETriage: A symbol-unified PE file reader for triage, built for multi-platform and multi-interface use.

Zeek plugin to detect and decrypt XOR-encrypted EXEs

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection

NFStream: a Flexible Network Data Analysis Framework.

WiFi, Bluetooth and Ethernet Intrusion Detection.

Open-source security framework for real-time event tracking, threat detection, and risk scoring. Monitors user behavior, detects fraud, bot attacks,…

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

A modular, skill-based autonomous Security Operations Center (SOC) agent that monitors OpenSearch/Elasticsearch data, builds RAG-based behavioral…

Serverless AWS security automation framework that ingests threat intelligence, applies ML-based anomaly detection (RCF, IP Insights), and enriches…

Monitor large transactions on Polymarket and Kalshi prediction markets with anomaly detection

Browser privacy-leak detector — eight detection modules, risk scoring, and per-account history, all in your browser.

Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis,…

Detects phi-structured C2 beacons that evade RITA and standard regularity-based detectors