
DShield-SIEM
DShield Sensor Log Collection with ELK

DShield Sensor Log Collection with ELK

Docker configuration to quickly setup your own Canarytokens.

A simple binary wrapper for DNS canarytokens.

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Comprehensive technical research on CVE-2026-43284 (Dirty Frag), including Linux kernel internals, root cause analysis, patch analysis, detection…

Softsensor Docker prototype

ZoneMinder is a free, open source Closed-circuit television software application developed for Linux which supports IP, USB and Analog cameras.


Security proxy for AI agents. Scans every message for prompt injection, PII, and secrets. Defense-in-depth: Go proxy + iptables firewall + eBPF…

Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.

Honeynet Project generic authenticated datafeed protocol

CVE-2020-0618 Honeypot

Defensive security demo: seL4 microkernel gateway protecting vulnerable ICS from CVE-2019-14462

A honeypot for the Log4Shell vulnerability (CVE-2021-44228).

PoC and Detection for CVE-2024-21626

CVE-2024-4577 PHP CGI Argument Injection - Detection Lab with Vagrant VMs and Wazuh SIEM rules

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Kernel-level security & attack response for Linux servers.