
ndaal_public_auditd
Best-practice Linux Auditd rule set with 14,956 MITRE ATT&CK-mapped rules, Ansible deployment role, and lint/test tooling for security monitoring and…

Best-practice Linux Auditd rule set with 14,956 MITRE ATT&CK-mapped rules, Ansible deployment role, and lint/test tooling for security monitoring and…

PacketFence is a fully supported, trusted, Free and Open Source network access control (NAC) solution. Boasting an impressive feature set including a…

A Linux Auditd rule set mapped to MITRE's Attack Framework

Best Practice Auditd Configuration

A Zeek package for the passive detection of "Ripple20" vulnerabilities in the Treck TCP/IP stack.

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

Zeek-based network detector for CVE-2022-24491, monitoring RPC portmap set and dump actions to identify exploit attempts in real-time traffic.

Blue Team detection lab created with Terraform and Ansible in Azure.

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections