
ImpossibleTravelLogAnalysis
Basic log analysis tool to detect impossible travel via IP address geographic information

Basic log analysis tool to detect impossible travel via IP address geographic information

A real-time traffic monitoring tool that detects and displays network traffic volume per IP address to identify potential DDoS attacks.

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

SigCorr is the first open-source tool to detect cross-protocol attack chains spanning SS7/MAP, Diameter S6a, and GTPv2-C through unified subscriber…


A network packet forensics tool for SSH

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Small tool to play with IOCs caused by Imageload events

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

Network monitoring tool that maps process-to-network connections, identifies cloud providers, and detects beaconing activity

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

Linux system-call monitor using ptrace to trace file, process, network, and memory activity, with namespace isolation and machine learning…

Ability to detect suspicious activity such as (WEP/WPA/WPS) attack by sniffing the air for wireless packets.