
cynative
Read-only AI agent that queries your cloud, code, and runtime infrastructure to surface misconfigurations, leaked secrets, and privilege escalation…

Read-only AI agent that queries your cloud, code, and runtime infrastructure to surface misconfigurations, leaked secrets, and privilege escalation…

ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.

SQL powered operating system instrumentation, monitoring, and analytics.

A Software as a Service (SaaS) log collection framework.

A secure low code deception runtime framework, leveraging AI for System Virtualization.

Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…

Open-source security framework for real-time event tracking, threat detection, and risk scoring. Monitors user behavior, detects fraud, bot attacks,…

AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK…

LLM-first deception framework: "The honeypot that talks back!™"

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Open-source framework for embedding realistic decoy routes and honey fields into APIs to detect attackers probing business logic, converting…


A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis,…



Host-based detection rules for the RCE vulnerability in the React JavaScript framework.

🦅 ZeroScout: The Autonomous Local & Cloud Threat Hunter. Visualize attacks in a live War Room, identify APT groups via Genetic Analysis, and…