
agentic-threat-hunting-framework
ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.

ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.

🦅 ZeroScout: The Autonomous Local & Cloud Threat Hunter. Visualize attacks in a live War Room, identify APT groups via Genetic Analysis, and…

Open-source security framework for real-time event tracking, threat detection, and risk scoring. Monitors user behavior, detects fraud, bot attacks,…

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Serverless AWS security automation framework that ingests threat intelligence, applies ML-based anomaly detection (RCF, IP Insights), and enriches…

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

Open-source framework for embedding realistic decoy routes and honey fields into APIs to detect attackers probing business logic, converting…

Kernel-runtime defense framework for AF_ALG vulnerabilities, featuring eBPF socket tracing, Ansible hardening, and a crypto auditor for drift…

Automatic security alert response framework by AWS Serverless Application Model

Host-based detection rules for the RCE vulnerability in the React JavaScript framework.

Crescendo is a swift based, real time event viewer for macOS. It utilizes Apple's Endpoint Security Framework.

A Software as a Service (SaaS) log collection framework.


Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis,…

SQL powered operating system instrumentation, monitoring, and analytics.

Cmd.exe Command Obfuscation Generator & Detection Test Harness

Evtx Log (xml) Browser