
Network_Assessment
With Wireshark or TCPdump, you can determine whether there is harmful activity on your network traffic that you have recorded on the network you…

With Wireshark or TCPdump, you can determine whether there is harmful activity on your network traffic that you have recorded on the network you…


A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

Enumerate various traits from Windows processes as an aid to threat hunting

A canary designed to minimize the impact from certain Ransomware actors

The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from…

This repository demonstrates a machine learning pipeline for detecting MITRE ATT&CK techniques from logs and enriching the output using a local LLM.

Open-source security framework for real-time event tracking, threat detection, and risk scoring. Monitors user behavior, detects fraud, bot attacks,…

amavis is a high-performance email content filter framework written in Perl.



Fingerprint SSH clients and servers.

A personal Windows SOC suite built in PowerShell — monitors network connections, resource usage, scheduled tasks and power events with severity…
