
mimikatz-detector-condrv
Kernel-mode filter driver that monitors ConDrv traffic to detect mimikatz execution in real-time, logging detection events via ETW for incident…

Kernel-mode filter driver that monitors ConDrv traffic to detect mimikatz execution in real-time, logging detection events via ETW for incident…

"A single malicious packet can own your device." — Android Security Team, Nov 2025

Defensive research toolkit for CVE-2025-31702 analysis, including lab scripts, parsers, and PoCs to validate Dahua device deployments and detect…

End-to-end simulation of detecting a root-less Android Drop Device (Casper) using Wazuh SIEM to capture Layer 7 attacks like Shellshock…

Step-by-step guide for deploying Microsoft Defender for Endpoint on Windows 10/11, including local script onboarding, device discovery, Log4j2…

Real-time SIEM dashboard for system log collection, USB device detection, and intrusion alerting. Built with Streamlit, Pandas, and Plotly for…

Check for and remediate conditions that make an IOS-XE device vulnerable to CVE-2023-20198

Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

Extract useful information from PANOS support file for CVE-2024-3400

SOC case analysis walkthrough demonstrating detection and response to CVE-2023-29357 privilege escalation in Microsoft SharePoint Server, including…