
auditd-attack
A Linux Auditd rule set mapped to MITRE's Attack Framework

A Linux Auditd rule set mapped to MITRE's Attack Framework

PowerShell Obfuscation Detection Framework

DejaVU - Open Source Deception Framework

A Software as a Service (SaaS) log collection framework.

Autonomous agent framework with structured memory, safety hooks, and loop management. Built by the agent that runs on it.

DropEngine provides a malleable framework for creating shellcode runners, allowing operators to choose from a selection of components and combine…

Modular framework for Windows UAC bypass attacks and mitigation, featuring DLL hijacking, fileless execution, and real-time monitoring to detect and…

The NoSQL Honeypot Framework

Bluewall is a firewall framework designed for offensive and defensive cyber professionals.

amavis is a high-performance email content filter framework written in Perl.

YAML-configurable low-interactive honeypot framework for deploying HTTP/HTTPS-based deception servers with built-in honeytraps and Datadog log…

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

🦅 ZeroScout: The Autonomous Local & Cloud Threat Hunter. Visualize attacks in a live War Room, identify APT groups via Genetic Analysis, and…

A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.

An Open-Source Pre and Post Callback-Based Framework for macOS Kernel Monitoring.

SQL powered operating system instrumentation, monitoring, and analytics.

Cmd.exe Command Obfuscation Generator & Detection Test Harness

PatrowlHears - Vulnerability Intelligence Center / Exploits