
osquery
SQL powered operating system instrumentation, monitoring, and analytics.

SQL powered operating system instrumentation, monitoring, and analytics.

Real-time monitoring and slowlog analysis for Valkey and Redis databases with anomaly detection, ACL auditing, and Prometheus metrics export.

Desktop monitoring and local security reviews for AI agents, with opt-in policy-controlled execution and MCP action tools. Windows primary;…

Modular security toolkit for autonomous agents providing static analysis, configuration auditing, runtime monitoring, and supply chain verification…

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Serverless AWS security automation framework that ingests threat intelligence, applies ML-based anomaly detection (RCF, IP Insights), and enriches…

Network anomaly detector that monitors raw packets to identify port scanning activity in real time, with flexible sniffing duration controls and live…

Open source entropy based invalid traffic detection and pre-bid filtering.

DNS Dashboard for hunting and identifying beaconing

A Bro package to identify connections that are bursting (lots of data and transferring quickly).

A real-time traffic monitoring tool that detects and displays network traffic volume per IP address to identify potential DDoS attacks.

Lightweight network intrusion detection engine capturing live traffic with libpcap. Detects SYN/ICMP floods, port scans, and signature-based web…

Zeek detector for QuasarRat

A Zeek based Mitre Caldera detector.

With Wireshark or TCPdump, you can determine whether there is harmful activity on your network traffic that you have recorded on the network you…

Detect HTTP stalling attacks like slowloris with Bro

Zeek detection for CVE-2020-16898-"Bad Neighbor"

Multi-engine Linux malware scanner with five detection stages (MD5, HEX pattern, YARA, ClamAV, statistical), real-time inotify monitoring,…