

Hardened Debian-based privacy OS with pre-integrated anonymity stack (Tor, VPN, DNSCrypt), anti-forensic tooling, SOC security center, and standalone…

Finding secrets in kernel and user memory

Analyzes Nginx access logs to detect SQL injection, scanner tools, webshells, and exploitation attempts, aiding system administrators in server…

A temporary mitigation against copy_fail variant (copyfail2_electric_boogaloo) - Unprivileged Linux LPE via xfrm ESP-in-UDP MSG_SPLICE_PAGES no-COW…

Exploit and detect CVE-2026-31431 vulnerabilities using a static binary that monitors system integrity and bypasses PAM authentication.




An agent to hotpatch the log4j RCE from CVE-2021-44228.

XZ-Utils工具库恶意后门植入漏洞(CVE-2024-3094)

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Live kernel signal observability tool using eBPF tracepoints to stream every signal raised on a Linux host, showing sender, target, disposition,…

Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Docker configuration to quickly setup your own Canarytokens.

A high interaction SSH honeypot