


Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…

BitLocker TPM+PIN Hardening Against CVE-2026-45585 (YellowKey)

Customer Assurance Operating System. Answer the security questionnaires your customers send you, once.



A personal Windows SOC suite built in PowerShell — monitors network connections, resource usage, scheduled tasks and power events with severity…



Official IP ranges for AI bot crawlers (OpenAI, Anthropic, Google, Microsoft, Perplexity). Weekly auto-updates.

Lightweight scriptable honeypot runner

My manifesto, and stories, images, and phun stuff

Citrix ADC (NetScaler) Honeypot. Supports detection for CVE-2019-19781 and login attempts

Discord bot for mitigating the aCropalypse vulnerability (CVE-2023-21036, CVE-2023-28303) by retroactively deleting vulnerable images

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

Web interface for Suricata ruleset management, threat hunting, and rule tuning with multi-source feed aggregation, transformation, and activity…