
awesome-linux-attack-forensics-purplelabs
This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Comprehensive technical research on CVE-2026-43284 (Dirty Frag), including Linux kernel internals, root cause analysis, patch analysis, detection…

Softsensor Docker prototype

Defensive security demo: seL4 microkernel gateway protecting vulnerable ICS from CVE-2019-14462

PoC and Detection for CVE-2024-21626

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!


Open-source deception platform that turns any Linux machine into a high-signal canary. Deploy tripwire sensors on files, ports, and network services…

A secure low code deception runtime framework, leveraging AI for System Virtualization.

An eBPF detection program for CVE-2022-0847


This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo…

Experimental Decoy Broker

Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities