
WELA
Audits Windows event log settings against best-practice guidelines and Sigma-rule detectability, with automated configuration for DFIR readiness.

Audits Windows event log settings against best-practice guidelines and Sigma-rule detectability, with automated configuration for DFIR readiness.

Best-practice Linux Auditd rule set with 14,956 MITRE ATT&CK-mapped rules, Ansible deployment role, and lint/test tooling for security monitoring and…

Python CLI/TUI for forensic triage of Ubuntu systems — detects and remediates persistence mechanisms with artifact collection, timeline correlation,…

StyleSmuggler (CVE-2026-75650) IOC toolkit for Magento Open Source and Adobe Commerce. Detect compromised stores, Rust implants, PHP web shells,…

Production-grade Security Baseline & Hardening Guide for Ubuntu 24.04/26.04 LTS. Kernel isolation, Emergency Panic Button, custom AppArmor/Firejail…

Trace every shell environment variable to its exact file and line origin. Audit shell configs for dead entries, duplicates, and orphaned files across…

Active Directory Forensic Toolkit : Detect & reconstruct AD attacks from Windows event logs (EVTX)

Systematic Linux kernel hardening project implementing KSPP-recommended settings, module blacklisting, and restricted environment configuration for…

Read, understand and silence the Windows GDID device identifier (the ID that tracked a hacker through a VPN). Verified on a real Win11 VM. Honest: it…

Production-ready detection & response queries for osquery

PowerShell script that automates the WinRE mitigation workflow for CVE-2026-45585, with verification steps and conditional commit to avoid…

Форензика после CVE-2026-41940 (cPanel/WHM) — bash-скрипт и чек-лист

linux security checks

Audix is a PowerShell tool to quickly configure the Windows Event Audit Policies for security monitoring

Documentation and scripts to properly enable Windows event logs.

Blue Team detection lab created with Terraform and Ansible in Azure.

Automate the creation of a lab environment complete with security tooling and logging best practices

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.