
coraza
Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

GlobaLeaks is a free and open-source whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

GitHub App to set and enforce security policies

Set of tools to analyze Windows sandboxes for exposed attack surface.

PacketFence is a fully supported, trusted, Free and Open Source network access control (NAC) solution. Boasting an impressive feature set including a…

Open-source YAML rule set for detecting and preventing email attacks including BEC, credential phishing, malware, and supporting threat hunting.

A Linux Auditd rule set mapped to MITRE's Attack Framework

Windows tool to list, get, set, protect, and unprotect process protection levels (PP/L) for debugging, inspection, and privilege escalation.

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

The remediation script should set the reg entries described in https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884 . The detection…

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

A repository of sysmon configuration modules

Best Practice Auditd Configuration

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

TAXII server implementation in Python from EclecticIQ

Blue Team detection lab created with Terraform and Ansible in Azure.

Tools and technical write-ups describing attacking techniques that rely on concealing code execution on Windows