
Loki
IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

A curated list of resources related to Industrial Control System (ICS) security.

Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

JA4+ is a suite of network fingerprinting standards

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)

Threat hunting command system for agentic IDEs

Honeynet Project generic authenticated datafeed protocol

Zeek package to detect exploitation attempts of CVE-2017-2741 targeting HP JetDirect printers via network traffic analysis.

Zeek package detecting CVE-2021-38647 (OMIGOD) exploit attempts by monitoring OMI/WMI traffic for missing Authorization headers and malicious SOAP…

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

Zeek package detecting Apache HTTP Server path traversal/RCE exploits (CVE-2021-41773, CVE-2021-42013) with payload capture and server header…

Technical analysis and detection guidance for CVE-2025-53770, a critical unauthenticated RCE vulnerability in Microsoft SharePoint Server exploited…

Tools for investigating Log4j CVE-2021-44228

A network detection package for CVE-2020-5902, a CVE10.0 vulnerability affecting F5 Networks, Inc BIG-IP devices.

NFStream: a Flexible Network Data Analysis Framework.

DShield Sensor Log Collection with ELK