
goaccess
GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through your browser.

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through your browser.

Runtime application self-protection engine that hooks into application servers to monitor and block malicious database queries, file operations, and…

A modular, skill-based autonomous Security Operations Center (SOC) agent that monitors OpenSearch/Elasticsearch data, builds RAG-based behavioral…

Digital forensics suite for DJI drones that parses telemetry files, extracts hidden data via steganography, visualizes flight paths, and detects…

With Wireshark or TCPdump, you can determine whether there is harmful activity on your network traffic that you have recorded on the network you…

Serverless AWS security automation framework that ingests threat intelligence, applies ML-based anomaly detection (RCF, IP Insights), and enriches…

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from…

Automated cloud security auditing tool that detects AK/SK credential misuse by periodically auditing cloud platform logs using anomaly detection,…

A Bro package to identify connections that are bursting (lots of data and transferring quickly).

Detects phi-structured C2 beacons that evade RITA and standard regularity-based detectors

AI-driven endpoint governance platform that monitors software usage, applies deterministic policy-based risk classification, and generates structured…

A real-time traffic monitoring tool that detects and displays network traffic volume per IP address to identify potential DDoS attacks.

Simple Anti-cheat library for applications that use C++ on windows. #PastedProtection

Network monitoring tool that maps process-to-network connections, identifies cloud providers, and detects beaconing activity

Forensic intelligence platform that analyzes files, correlates threat indicators, maps behavior to MITRE ATT&CK, and generates actionable security…

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

A network packet forensics tool for SSH