
so-crates
SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Automated IP ban service that detects failed login attempts from event logs and files, blocking attackers on Windows and Linux via firewall…

KQL detection rules for Microsoft Sentinel and Defender XDR covering the bikini/exploitarium anonymous disclosure — a personal research archive of…

With Wireshark or TCPdump, you can determine whether there is harmful activity on your network traffic that you have recorded on the network you…

Daemon to ban hosts that cause multiple authentication errors

Bilgisayarınıza yapılan ARP Spoofing saldırılarını tespit eden ARP Spoof Detector Scripti.

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

NetworkAssessment: Network Compromise Assessment Tool

Pre-execution intent verification for AI agents. Audits what your AI is about to do, not what it says. Zero dependencies, deterministic, hash-sealed.

Open-source deception platform that turns any Linux machine into a high-signal canary. Deploy tripwire sensors on files, ports, and network services…

Conveigh is a Windows PowerShell LLMNR/NBNS spoofer detection tool

PCAPs and Suricata signatures for detecting OpenSSL CVE-2022-3602 exploitation attempts, including malicious client/server traffic and legitimate…

Endpoint behavior monitoring and analysis system for processes, files, registry, and networks. Supports scripting, extensions, and plugins for…

Windows honeypot using ProjFS to project decoy files that trigger Event Log and desktop alerts when accessed, with SMB remote session logging for…

Security Tool to detect arp poisoning attacks

Lightweight network intrusion detection engine capturing live traffic with libpcap. Detects SYN/ICMP floods, port scans, and signature-based web…

Primary data pipelines for intrusion detection, security analytics and threat hunting

teamcity teamcity-CVE-2026-63077 exploitation pcap