
clawdstrike
Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

eBPF-powered silent observer for containerized runtimes, built for malware analysis sandboxes and Agentic AI monitoring.

A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine…

The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

A Smart Log4Shell/Log4j/CVE-2021-44228 Scanner

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use…

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

Labtainers: A Docker-based cyber lab framework

The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis

Agentic AI memory with Ebbinghaus forgetting curve decay. +16pp better recall than Mem0 on LoCoMo.

A sandbox escape based on the proof-of-concept (CVE-2018-4087) by Rani Idan (Zimperium)

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.

OS X Auditor is a free Mac OS X computer forensics tool

Firmware Analysis and Comparison Tool