
packetfence
PacketFence is a fully supported, trusted, Free and Open Source network access control (NAC) solution. Boasting an impressive feature set including a…

PacketFence is a fully supported, trusted, Free and Open Source network access control (NAC) solution. Boasting an impressive feature set including a…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

A repository of sysmon configuration modules

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

Set of tools to analyze Windows sandboxes for exposed attack surface.

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

Best Practice Auditd Configuration

GlobaLeaks is a free and open-source whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.

GitHub App to set and enforce security policies

A Linux Auditd rule set mapped to MITRE's Attack Framework

Windows tool to list, get, set, protect, and unprotect process protection levels (PP/L) for debugging, inspection, and privilege escalation.

Open-source YAML rule set for detecting and preventing email attacks including BEC, credential phishing, malware, and supporting threat hunting.

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

Tools and technical write-ups describing attacking techniques that rely on concealing code execution on Windows

TAXII server implementation in Python from EclecticIQ

Blue Team detection lab created with Terraform and Ansible in Azure.

MDE relies on some of the Audit settings to be enabled

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections