
DShield-SIEM
DShield Sensor Log Collection with ELK

DShield Sensor Log Collection with ELK


Docker configuration to quickly setup your own Canarytokens.

Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…

Comprehensive technical research on CVE-2026-43284 (Dirty Frag), including Linux kernel internals, root cause analysis, patch analysis, detection…

Windows Process Lockdown Tool using Job Objects

CVE-2026-33634 (CVSS 9.4) — The most impactful CI/CD supply chain attack of 2026 so far.

Securekit is a protocol-agnostic security kernel that enforces zero-trust, sandboxed execution for AI tool use. It sits between any LLM or agent…

Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit.

OWASP Honeypot, Automated Deception Framework.

CVE-2023-46604 (Apache ActiveMQ RCE Vulnerability) and focused on getting Indicators of Compromise.

CVE-2020-0618 Honeypot

An ssh honeypot with the XZ backdoor. CVE-2024-3094

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…