
osquery
SQL powered operating system instrumentation, monitoring, and analytics.

SQL powered operating system instrumentation, monitoring, and analytics.

Endpoint behavior monitoring and analysis system for processes, files, registry, and networks. Supports scripting, extensions, and plugins for…

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…


Command-line packet analyzer for network monitoring and data acquisition, capturing and displaying network traffic for troubleshooting, analysis, and…

Command-line packet analyzer for network monitoring and data acquisition, capturing and displaying network traffic for troubleshooting and security…

Command-line packet analyzer for network monitoring and data acquisition, capturing and displaying network traffic for troubleshooting and security…

Defensive PoC decoy for CVE-2025-59287 (WSUS) - emulates WSUS endpoints, captures request bodies and metadata, saves evidence for forensic analysis,…

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

A wireshark plugin to instrument ETW

Advanced SMB Honeypot: CVE-2025-33073 Research & Implementation

This project is now part of @mitmproxy.

Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)

CVE-2026-30784: RustDesk hbbs Traffic Amplification PoC & PCAP Analysis

CVE-2019-19781 Attack Triage Script

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

Monitoring Registry and File Changes in Windows

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.