
tirreno
Open-source security framework for real-time event tracking, threat detection, and risk scoring. Monitors user behavior, detects fraud, bot attacks,…

Open-source security framework for real-time event tracking, threat detection, and risk scoring. Monitors user behavior, detects fraud, bot attacks,…

Crescendo is a swift based, real time event viewer for macOS. It utilizes Apple's Endpoint Security Framework.


Hubble is a modular, open-source security compliance framework. The project provides on-demand profile-based auditing, real-time security event…


Serverless AWS security automation framework that ingests threat intelligence, applies ML-based anomaly detection (RCF, IP Insights), and enriches…

Read-only AI agent that queries your cloud, code, and runtime infrastructure to surface misconfigurations, leaked secrets, and privilege escalation…

Event-driven AWS security misconfiguration detection framework that monitors multiple accounts in real-time, triggering alerts via Lambda for IAM,…

Automatic security alert response framework by AWS Serverless Application Model

Open-source framework for embedding realistic decoy routes and honey fields into APIs to detect attackers probing business logic, converting…

A secure low code deception runtime framework, leveraging AI for System Virtualization.

ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.

OWASP Honeypot, Automated Deception Framework.

Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis,…

AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK…

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…