
ShellSweep
Entropy-based web shell detection tool with multi-layered analysis including pattern matching, heuristic rules, and YARA support. Scans directories…

Entropy-based web shell detection tool with multi-layered analysis including pattern matching, heuristic rules, and YARA support. Scans directories…

Analyzes SSH packet captures using machine learning to predict reverse tunnels, keystrokes, data exfiltration, and authentication methods for…

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

Cross-platform PE surface analysis tool for malware triage with 25 anomaly detection rules, OPSEC analysis, build fingerprinting, and overlay…

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

Active Directory enumeration and attack path analysis tool that collects domain objects, ACLs, sessions, and credentials into a SQL database,…

On-device runtime security for AI agents with 515+ detection rules and ML ensemble to stop prompt injection, jailbreaks, and tool attacks in under…

A tool for malicious behavior detection in IoT devices

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

Small tool to play with IOCs caused by Imageload events

Automated cloud security auditing tool that detects AK/SK credential misuse by periodically auditing cloud platform logs using anomaly detection,…

Basic log analysis tool to detect impossible travel via IP address geographic information

Runtime security gateway for AI agents: cryptographically attests tool calls, enforces policies, sandboxes execution, and logs tamper-evident audit…

A real-time traffic monitoring tool that detects and displays network traffic volume per IP address to identify potential DDoS attacks.

Passive cross-protocol attack detection tool for mobile core networks. Correlates SS7/MAP, Diameter S6a, and GTPv2-C events to detect location…

Network monitoring tool that maps process-to-network connections, identifies cloud providers, and detects beaconing activity

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation.…