
Network_Assessment
With Wireshark or TCPdump, you can determine whether there is harmful activity on your network traffic that you have recorded on the network you…

With Wireshark or TCPdump, you can determine whether there is harmful activity on your network traffic that you have recorded on the network you…

Bilgisayarınıza yapılan ARP Spoofing saldırılarını tespit eden ARP Spoof Detector Scripti.

Conveigh is a Windows PowerShell LLMNR/NBNS spoofer detection tool

Windows honeypot using ProjFS to project decoy files that trigger Event Log and desktop alerts when accessed, with SMB remote session logging for…

Security Tool to detect arp poisoning attacks

PCAPs and Suricata signatures for detecting OpenSSL CVE-2022-3602 exploitation attempts, including malicious client/server traffic and legitimate…

Lightweight network intrusion detection engine capturing live traffic with libpcap. Detects SYN/ICMP floods, port scans, and signature-based web…

Primary data pipelines for intrusion detection, security analytics and threat hunting

A network detection package for CVE-2020-16898 (Windows TCP/IP Remote Code Execution Vulnerability)

Zeek script to detect exploitation attempts of CVE-2022-21449 targeting TLS clients

teamcity teamcity-CVE-2026-63077 exploitation pcap

Repo containing lua scripts and PCAP to find CVE-2020-0601 exploit attempts via network traffic

Corelight@Home script

Detection of rootkit file hiding activities through analysis of shifts in kernel function execution times.

Mapping Corelight or Zeek data to Elastic Common Schema logs

A Zeek OpenVPN protocol analyzer, based on Spicy.

This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo…

Zeek package to detect CVE-2022-21907 HTTP exploit attempts by analyzing packet captures for malformed requests and triggering alerts.