
coraza
Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Set of tools to assess and improve LLM security.

PacketFence is a fully supported, trusted, Free and Open Source network access control (NAC) solution. Boasting an impressive feature set including a…

0-day malware detection for binaries, source & scripts (that doesn't suck)

GitHub App to set and enforce security policies

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

This chef cookbook provides security configuration for mysql.

GlobaLeaks is a free and open-source whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

Corelight Dashboards and Parsers for Sentinel One Singularity

Kernel module using ftrace to block AF_ALG/AEAD requests, mitigating CVE-2026-31431 without requiring LSM BPF. Provides logging and easy compilation…

Best Practice Auditd Configuration

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

TAXII server implementation in Python from EclecticIQ

Set of tools to analyze Windows sandboxes for exposed attack surface.

Blue Team detection lab created with Terraform and Ansible in Azure.

The remediation script should set the reg entries described in https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884 . The detection…

Windows tool to list, get, set, protect, and unprotect process protection levels (PP/L) for debugging, inspection, and privilege escalation.