
rvbbit-arsenal
Offensive & defensive Linux kernel security research focused on rootkit behavior, observable artifacts and detection.

Offensive & defensive Linux kernel security research focused on rootkit behavior, observable artifacts and detection.

Open-source alerting engine for time-series monitoring data. Connects to Prometheus, VictoriaMetrics, ElasticSearch, and other data sources. Supports…

DEPRECATED - MozDef: Mozilla Enterprise Defense Platform


Re-play Security Events

Curated database of vulnerable and malicious Windows drivers with YARA, Sigma, ClamAV, and Sysmon detection rules for proactive threat hunting and…

A MITM (monster-in-the-middle) detection tool. Used to build MALCOLM:

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

StalkPhish - The Phishing kits stalker, harvesting phishing kits for investigations.

DARKSURGEON is a Windows packer project to empower incident response, digital forensics, malware analysis, and network defense.

This project is a SIEM with SIRP and Threat Intel, all in one.

Hubble is a modular, open-source security compliance framework. The project provides on-demand profile-based auditing, real-time security event…

Live hunting of code injection techniques

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

Portable forensic acquisition tool for Android devices that collects relevant data via USB debugging to identify potential spyware or compromise…

Rules generated from our investigations.

Blue Team detection lab created with Terraform and Ansible in Azure.

AI 驱动的 SOC 仿真平台