
AiSOC
Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation.…

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation.…

This project aims to compare and evaluate the telemetry of various EDR products.

Wire-level proxy firewall for AI agents that intercepts and gates SQL, Kubernetes, and HTTP traffic using HCL rules, with per-process tunnel…

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

An agent to hotpatch the log4j RCE from CVE-2021-44228.

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

A user-mode application authorization system for MacOS written in Swift

PoC memory injection detection agent based on ETW, for offensive and defensive research purposes

Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.

Open-source EDR for AI agents. Monitor processes, files, network, and behavior of autonomous AI agents.

Security proxy for AI agents. Scans every message for prompt injection, PII, and secrets. Defense-in-depth: Go proxy + iptables firewall + eBPF…

Autonomous agent framework with structured memory, safety hooks, and loop management. Built by the agent that runs on it.


Lightweight macOS detection agent built on Santa’s Endpoint Security telemetry.

Rust-based endpoint security agent with application whitelisting, attack detection, and prevention. Supports multiple platforms with audited…

A Byte Buddy Java agent-based fix for CVE-2021-44228, the log4j 2.x "JNDI LDAP" vulnerability.