
tetragon
eBPF-based Security Observability and Runtime Enforcement

eBPF-based Security Observability and Runtime Enforcement

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

Reverse Shell Detection with Machine Learning

A Linux Host-based Intrusion Detection System based on eBPF.

Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Labtainers: A Docker-based cyber lab framework

XDP Based Lightweight and Fast Firewall

Lightweight Python-based IDS that monitors network traffic in real-time using Scapy, detecting DoS/DDoS attacks via per-IP request rate analysis with…

Detection rules and analysis for Dirty Frag (CVE-2026-43284/CVE-2026-43500) Linux kernel LPE vulnerability. Based on community research and health…

A Zeek protocol analyzer for the Facefish rootkit, based on Spicy.

Detection of Linux Malware C2 RedXOR - demonstration