
Hunt-Weird-ImageLoads
Small tool to play with IOCs caused by Imageload events

Small tool to play with IOCs caused by Imageload events

Detection rule validation

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research

Automated Network Security with Rust: Detecting and Blocking Port Scanners

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

Corelight@Home script

A real-time traffic monitoring tool that detects and displays network traffic volume per IP address to identify potential DDoS attacks.

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

SigCorr is the first open-source tool to detect cross-protocol attack chains spanning SS7/MAP, Diameter S6a, and GTPv2-C through unified subscriber…

Rust tool to detect cell site simulators on an orbic mobile hotspot

Ability to detect suspicious activity such as (WEP/WPA/WPS) attack by sniffing the air for wireless packets.

A tool to generate Snort rules based on public IP reputation data


Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

PacketFence is a fully supported, trusted, Free and Open Source network access control (NAC) solution. Boasting an impressive feature set including a…

a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…