
siper
XDP Based Lightweight and Fast Firewall

XDP Based Lightweight and Fast Firewall

High fidelity defensive security lab simulating a DoD aligned enterprise network with Active Directory, VLAN segmentation, STIG based hardening,…

Lightweight Python-based IDS that monitors network traffic in real-time using Scapy, detecting DoS/DDoS attacks via per-IP request rate analysis with…

Lightweight, container-free sandbox for running commands with network and filesystem restrictions

Whoami provides enhanced privacy, anonymity for Debian and Arch based linux distributions

Crescendo is a swift based, real time event viewer for macOS. It utilizes Apple's Endpoint Security Framework.

A Linux Host-based Intrusion Detection System based on eBPF.

The Sigma command line interface based on pySigma

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

PoC memory injection detection agent based on ETW, for offensive and defensive research purposes

ETW based POC to identify direct and indirect syscalls

First iteration of ML based Feedback WAF

A host based IDS written in C# Targetted at Metasploit

Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).

Kernel-level security engine using eBPF-LSM to enforce file access policies based on process lineage, protecting sensitive data from supply-chain…

PowerShell script that automatically tests CMD bypass methods on Windows, evaluates results, calculates a security score, and provides hardening…
