
bpfjailer
eBPF LSM based Mandatory Access Control and jailer

eBPF LSM based Mandatory Access Control and jailer

Extracts LSA secrets and DPAPI keys from Windows registry hives via existing or newly created VSS shadow copies, with an inline regf parser and…

Parse and visualize /proc/self/environ on compromised Linux boxes — categorizes env vars by tech stack (AWS, Django, Rails, NodeJS, MySQL, K8s,…

DShield Sensor Log Collection with ELK

Automatically generated Sysmon parser for Azure Sentinel


Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Proof-of-concept telemetry collector for Windows LDAP client activity via ETW, logging structured events to Event Viewer with a Sentinel parser for…

A Zeek OpenVPN protocol analyzer plugin.

Chronicle parser for CORELIGHT and related information.

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

Wire-level proxy firewall for AI agents that intercepts and gates SQL, Kubernetes, and HTTP traffic using HCL rules, with per-process tunnel…

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

Scan files or process memory for CobaltStrike beacons and parse their configuration

Centralized IoC scanner that deploys Loki across endpoints, collects detection results, and parses logs into CSV for incident response and forensic…