
rita
Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

CVE-2020-0618 Honeypot

Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)

Threat hunting command system for agentic IDEs

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Detect Tactics, Techniques & Combat Threats

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

Digital forensics and incident response tool using YARA rules to scan Citrix NetScaler core dumps, disk images, and live hosts for signs of…

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…


Runs custom filters on Elasticsearch and alerts on matches

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

A repository of sysmon configuration modules

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

A network packet forensics tool for SSH