
azure-sentinel-detection-engineering
9 MITRE ATT&CK-mapped KQL detections on a live Microsoft Sentinel + Defender XDR environment (control-plane, endpoint, identity), with a PR-gated…

9 MITRE ATT&CK-mapped KQL detections on a live Microsoft Sentinel + Defender XDR environment (control-plane, endpoint, identity), with a PR-gated…

OSINT intelligence on any IP, domain, or ASN

IOC scanner for agentic AI coding tools — detects Mini Shai-Hulud, Gemini CLI RCE, Cursor CVE-2026-26268, and DPRK PromptMink.

This repository provides a practical comparison of breach intelligence, dark web monitoring, and identity exposure services, with a focus on factors…

Security gateway for MCP servers with per-tool policy enforcement, Ed25519-signed audit receipts, and shadow-mode logging. Supports Cedar, OPA, and…

Unified dashboard to monitor, govern, and audit AI agents in real-time. Enforce budgets, detect policy violations, and export compliance reports for…

Map tracking ransomware, by OCD World Watch team

Portable forensic acquisition tool for Android devices that collects relevant data via USB debugging to identify potential spyware or compromise…

Analyzes a dark web leak of 15,000+ Fortinet devices compromised via CVE-2022-40684, providing IOCs, impacted versions, and a Python script to…

Parses the System Snapshot from an Ivanti Connect Secure applicance to identify possible IOCs related to CVE-2023-46805, CVE-2024-21887 and…

Zeek Notice Telegram (ZeekJS edition)

Runs custom filters on Elasticsearch and alerts on matches

This work includes testing and improvement tools for CVE-2021-44228(log4j).

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

A Canary which fires when uninstalled

Live hunting of code injection techniques