
phantom-grid
An eBPF-powered Active Defense system that turns your Linux server into a deceptive honeypot. Features transparent traffic redirection, OS…

An eBPF-powered Active Defense system that turns your Linux server into a deceptive honeypot. Features transparent traffic redirection, OS…

JA4+ is a suite of network fingerprinting standards

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Open-source detection engineering tool that traces security detections end to end and identifies the first failing stage.

RPi3+ Network Cracker Setup Tool

A tool to monitor local network traffic for possible security vulnerabilities. Warns user against possible nmap scans, Nikto scans, credentials sent…

Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research

Monitors Asterisk authentication logs and automatically bans IPs with repeated failed login attempts using iptables, with configurable thresholds and…

Rust tool to detect cell site simulators on an orbic mobile hotspot

Sniffles: Packet Capture Generator for IDS and Regular Expression Evaluation

A tool for malicious behavior detection in IoT devices

PacketFence is a fully supported, trusted, Free and Open Source network access control (NAC) solution. Boasting an impressive feature set including a…

A simple tool to detect NBT-NS and LLMNR spoofing (and messing with them a bit)

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

A binary and file access authorization system for macOS.