
siem-threat-detection-lab
Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…

Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…


IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…


Hash-based malware scanner for incident response. Scans files recursively using known malware hashes, supports multithreading, extension filtering,…


FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

An easy to use, light-weight, on-demand virus scanner for Linux systems. For additional help, see the <a…

A high interaction SSH honeypot

Bash and PowerShell scripts to scan a local filesystem for Log4j .jar files which could be vulnerable to CVE-2021-44228 aka Log4Shell.