
opencanary
Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and…

Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and…

Open-source antivirus engine for detecting trojans, viruses, and malware via signature-based scanning; includes a daemon, on-demand CLI, and…

Daemon to ban hosts that cause multiple authentication errors

The Shadow Daemon web application firewall server

CTF-style Docker lab for CVE-2026-41651 (Pack2TheRoot): PackageKit permissive-polkit local privilege escalation

USB port access control tool for Debian with whitelist management, automatic background scanning daemon, and CLI interface to block or allow USB…

eBPF LSM program that blocks AF_ALG socket creation to mitigate CVE-2026-31431, with userspace daemon logging denied attempts via ring buffer.


Daemon to randomize tcp_challenge_ack_limit to prevent side channel attacks CVE-2016-5696

eBPF-based runtime detector for container breakout vulnerabilities in runc and Docker, monitoring syscalls and Docker daemon calls to detect…

eBPF-based daemon to mitigate CVE-2026-31431 on systems where `algif_aead` is built into the kernel, without a reboot!

Honeypot for Intel's AMT Firmware Vulnerability CVE-2017-5689