
NetAlertX
Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.

Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.

Labtainers: A Docker-based cyber lab framework

A smart gateway to stop cyber criminals - Sponsored by Falcon Guard

This project is a SIEM with SIRP and Threat Intel, all in one.

⭐ ⭐ Distributed tcpdump for cloud native environments ⭐ ⭐

Programmatically create hunting rules for deserialization exploitation with multiple keywords, gadget chains, object types, encodings, and rule types

PEAK Baseline Threat Hunt dashboards for Security Onion 3.0 — covering DNS, HTTP, TLS, SMB, Kerberos, SSH, RDP, DCE/RPC, LDAP, Modbus, DNP3,…


A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).

tshark + ELK analytics virtual machine

A high interaction SSH honeypot

Bro/Zeek script for detecting Apache Struts CVE-2017-5638 reconnaissance, compromise, and malware download tracking with automated IP extraction.