
plague
Default Detections for EDR

Default Detections for EDR

Detection of rootkit file hiding activities through analysis of shifts in kernel function execution times.

My experiments in weaponizing ONOS applications (https://github.com/opennetworkinglab/onos)

Framework for implementing Network Intrusion Detection Systems (NIDS) aimed at identifying anomalies in network flows using Federated Learning models.

Basic log analysis tool to detect impossible travel via IP address geographic information

A Zeek OSPF packet analyzer based on Spicy.

Daemon to randomize tcp_challenge_ack_limit to prevent side channel attacks CVE-2016-5696

This repository hosts a multimodal web attack dataset (MWAD) to advance AI-driven threat detection research.

Leitwacht control plane — runtime security for GitLab Runner CI/CD: policy authoring, multi-tenancy, audit, GitLab integration

Enrich the conn.log with EDR data

Production-grade tool for detecting & remediating CVE-2026-0622 (Ghost Admin privilege escalation & master key exposure in 5G core software).