
openrasp
Runtime application self-protection engine that hooks into application servers to monitor and block malicious database queries, file operations, and…

Runtime application self-protection engine that hooks into application servers to monitor and block malicious database queries, file operations, and…

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…

Signatures and IoCs from public Volexity blog posts.

PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs

A network packet forensics tool for SSH

The Sigma command line interface based on pySigma

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

ioc2rpz is a place where threat intelligence meets DNS.

Open-source deception platform that turns any Linux machine into a high-signal canary. Deploy tripwire sensors on files, ports, and network services…

A script to configure a TP-Link MR3040 running OpenWRT into a simple, yet powerful penetration-testing "dropbox".

TheLightScope

Windows honeypot using ProjFS to project decoy files that trigger Event Log and desktop alerts when accessed, with SMB remote session logging for…


Public repository of Sigma and YARA rules created by Synacktiv

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…