
pyrasp
Runtime Application Self Protection for Python web servers, serverless functions and MCP servers, detecting attacks, prompt injection and data leaks…

Runtime Application Self Protection for Python web servers, serverless functions and MCP servers, detecting attacks, prompt injection and data leaks…

Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

Critical buffer validation bypass in deserialize_tensor() (llama.cpp < b8492). Null tensor buffer skips bounds check, enabling unauthenticated…

Detection, mitigation, and IOC toolkit for Copy Fail CVE-2026-31431 Linux kernel page-cache privilege escalation

A curated list of resources related to Industrial Control System (ICS) security.

DShield Sensor Log Collection with ELK

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Detects forged Kerberos tickets by dumping session and ticket data, scoring anomalies, and generating Windows event-log indicators for SIEM-based…

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

teamcity teamcity-CVE-2026-63077 exploitation pcap

MysqlHoneypot

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Detect HTTP stalling attacks like slowloris with Bro

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

Zeek package for detecting PetitPotam NTLM relay attacks via EFS DCERPC over unencrypted SMB, distinguishing successful and unsuccessful exploit…

Structured guide to threat hunting using Zeek logs, aligned with MITRE ATT&CK framework for proactive detection of adversary tactics and techniques.

Top DNS Measurement for Bro

A Zeek OpenVPN protocol analyzer plugin.