
amthoneypot
Honeypot for Intel's AMT Firmware Vulnerability CVE-2017-5689

Honeypot for Intel's AMT Firmware Vulnerability CVE-2017-5689

Daemon to ban hosts that cause multiple authentication errors

Open-source antivirus engine for detecting trojans, viruses, and malware via signature-based scanning; includes a daemon, on-demand CLI, and…

eBPF-based daemon to mitigate CVE-2026-31431 on systems where `algif_aead` is built into the kernel, without a reboot!

Daemon to randomize tcp_challenge_ack_limit to prevent side channel attacks CVE-2016-5696

USB port access control tool for Debian with whitelist management, automatic background scanning daemon, and CLI interface to block or allow USB…

eBPF LSM program that blocks AF_ALG socket creation to mitigate CVE-2026-31431, with userspace daemon logging denied attempts via ring buffer.

eBPF-based runtime detector for container breakout vulnerabilities in runc and Docker, monitoring syscalls and Docker daemon calls to detect…

The Shadow Daemon web application firewall server

Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and…


CTF-style Docker lab for CVE-2026-41651 (Pack2TheRoot): PackageKit permissive-polkit local privilege escalation