
DShield-SIEM
DShield Sensor Log Collection with ELK

DShield Sensor Log Collection with ELK

GitHub mirror of the Linux Kernel's audit repository

Detection of Linux Malware C2 RedXOR - demonstration

Mapping Corelight or Zeek data to Elastic Common Schema logs

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

A Wordpress Honeypot

PacketFence is a fully supported, trusted, Free and Open Source network access control (NAC) solution. Boasting an impressive feature set including a…


Detection, Exploit and Mitigation for CVE 2023 46604.

Zeek detection logic for CVE-2022-30216.

End-to-end simulation of detecting a root-less Android Drop Device (Casper) using Wazuh SIEM to capture Layer 7 attacks like Shellshock…

LLMNR/NBNS/mDNS Spoofing Detection Toolkit

A utility to safely generate malicious network traffic patterns and evaluate controls.

Security event correlation engine for ELK stack