
waf-fu
Terminal UI for browsing and replaying AWS WAF v2 logs from CloudWatch, S3, and the sampling API, with YAML filtering, auth detection, and…

Terminal UI for browsing and replaying AWS WAF v2 logs from CloudWatch, S3, and the sampling API, with YAML filtering, auth detection, and…

Host-local Linux security orchestrator enforcing nftables policy with HIDS/HIPS telemetry, bounded threat-intelligence feeds, out-of-band WAAP log…

SOC operations content for Microsoft Sentinel, including hunting queries, incident response playbooks, and security event analysis for Azure cloud…

Detection signatures for CVE-2026-41940 and shemas for cPanel logs

Collection of Google Cloud solution examples and operational utilities for audit log monitoring, DLP de-identification, encryption key management,…

DEF CON Cloud Village workshop slides teaching KQL for cloud security log analysis, with practical exercises in a shared Azure Log Analytics…

Automatically generated Sysmon parser for Azure Sentinel

Chronicle parser for CORELIGHT and related information.

CI pipeline for building nxlog-ce on Ubuntu with CVE-2020-35488 vulnerability detection, enabling automated log collection and security auditing in…

KQL para deteccion de CVE-2025-21333 en Sentinel

Microsoft Sentinel SIEM Log Source Analyzer

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

CVE-2021-38647 - POC to exploit unauthenticated RCE #OMIGOD

Zero-code K8s sidecar for log sanitization. Detects secrets via Entropy Analysis, preserves JSON integrity, and redacts PII deterministically. 🛡️

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Security event correlation engine for ELK stack

A security toolkit for Amazon S3

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS