
sysmon-parser
Automatically generated Sysmon parser for Azure Sentinel

Automatically generated Sysmon parser for Azure Sentinel

Chronicle parser for CORELIGHT and related information.

Parse and visualize /proc/self/environ on compromised Linux boxes — categorizes env vars by tech stack (AWS, Django, Rails, NodeJS, MySQL, K8s,…

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Scan files or process memory for CobaltStrike beacons and parse their configuration

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

Proof-of-concept telemetry collector for Windows LDAP client activity via ETW, logging structured events to Event Viewer with a Sentinel parser for…

Centralized IoC scanner that deploys Loki across endpoints, collects detection results, and parses logs into CSV for incident response and forensic…

Extracts LSA secrets and DPAPI keys from Windows registry hives via existing or newly created VSS shadow copies, with an inline regf parser and…

Security-aware HTTP protocol parser library used by IDS/IPS engines to inspect and normalize HTTP traffic for threat detection.


Wire-level proxy firewall for AI agents that intercepts and gates SQL, Kubernetes, and HTTP traffic using HCL rules, with per-process tunnel…

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

DShield Sensor Log Collection with ELK

A Zeek OpenVPN protocol analyzer plugin.

eBPF LSM based Mandatory Access Control and jailer