
msticpy
Microsoft Threat Intelligence Security Tools

Microsoft Threat Intelligence Security Tools

Collection of KQL queries

A machine learning toolkit for log parsing [ICSE'19, DSN'16]

Deep Learning models for network traffic classification


AI-based, context-driven network device ranking

Suricata rules for network anomaly detection

A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon


Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

amavis is a high-performance email content filter framework written in Perl.


A canary designed to minimize the impact from certain Ransomware actors

First iteration of ML based Feedback WAF

3D multi-domain tactical intelligence map — live ships, flights, satellites, cables & space weather in the browser. Time scrubbing, scenario replay,…


Pre-execution intent verification for AI agents. Audits what your AI is about to do, not what it says. Zero dependencies, deterministic, hash-sealed.

Research related to the Power Tracks discovered in market microstructure.