
WindowsMemPageDelta
A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection

A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection

Zeek plugin to detect and decrypt XOR-encrypted EXEs

Linux system-call monitor using ptrace to trace file, process, network, and memory activity, with namespace isolation and machine learning…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Runtime application self-protection engine that hooks into application servers to monitor and block malicious database queries, file operations, and…

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

The StackRox Kubernetes Security Platform performs a risk analysis of the container environment, delivers visibility and runtime alerts, and provides…

Java library to analyse Portable Executable files with a special focus on malware analysis and PE malformation robustness

Ability to detect suspicious activity such as (WEP/WPA/WPS) attack by sniffing the air for wireless packets.

OS-level monitor for AI agents: observes processes, file access, and network activity on the local machine and attributes each event to an agent…

Enumerate various traits from Windows processes as an aid to threat hunting

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

Network anomaly detector that monitors raw packets to identify port scanning activity in real time, with flexible sniffing duration controls and live…

ETW based POC to identify direct and indirect syscalls

A canary designed to minimize the impact from certain Ransomware actors

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

Collects and analyzes AD and Azure AD authentication logs to detect lateral movement attacks using graph-based anomaly detection, visualizing…

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…